Skip to main content
QUICK REVIEW

[論文レビュー] Consumer, Commercial and Industrial IoT (In)Security: Attack Taxonomy and Case Studies

Christos Xenofontos, Ioannis Zografopoulos|arXiv (Cornell University)|May 14, 2021
Network Security and Intrusion Detection参考文献 70被引用数 11
ひとこと要約

本論文は、消費者、商業、産業用IoTシステムを対象とした階層的攻撃分類法を提案し、デバイス、インfra構造、通信、サービスの各レイヤーにわたり脅威を分類する。9件の事実上の事例研究を用いて、脆弱性、攻撃ベクトル、緩和戦略を特定し、多様な分野におけるIoTセキュリティを前もって対応できる体系的フレームワークを提供する。

ABSTRACT

Internet of Things (IoT) devices are becoming ubiquitous in our lives, with applications spanning from the consumer domain to commercial and industrial systems. The steep growth and vast adoption of IoT devices reinforce the importance of sound and robust cybersecurity practices during the device development life-cycles. IoT-related vulnerabilities, if successfully exploited can affect, not only the device itself, but also the application field in which the IoT device operates. Evidently, identifying and addressing every single vulnerability is an arduous, if not impossible, task. Attack taxonomies can assist in classifying attacks and their corresponding vulnerabilities. Security countermeasures and best practices can then be leveraged to mitigate threats and vulnerabilities before they emerge into catastrophic attacks and ensure overall secure IoT operation. Therefore, in this paper, we provide an attack taxonomy which takes into consideration the different layers of IoT stack, i.e., device, infrastructure, communication, and service, and each layer's designated characteristics which can be exploited by adversaries. Furthermore, using nine real-world cybersecurity incidents, that had targeted IoT devices deployed in the consumer, commercial, and industrial sectors, we describe the IoT-related vulnerabilities, exploitation procedures, attacks, impacts, and potential mitigation mechanisms and protection strategies. These (and many other) incidents highlight the underlying security concerns of IoT systems and demonstrate the potential attack impacts of such connected ecosystems, while the proposed taxonomy provides a systematic procedure to categorize attacks based on the affected layer and corresponding impact.

研究の動機と目的

  • 消費者、商業、産業分野におけるIoTデバイスの急増に伴うセキュリティリスクの増大に取り組むこと。
  • デバイス、インfra構造、通信、サービスレイヤーの脆弱性を悪用するIoT固有の攻撃ベクトルを特定・分類すること。
  • IoTエコシステムを標的とした事実上のサイバーインシデントを分析し、共通の攻撃パターンと構造的弱みを暴露すること。
  • 各IoTセクターの独自の運用制約と脅威表面を踏まえた、実行可能な緩和戦略とセキュリティ対策を提案すること。
  • 包括的な脅威モデリングを可能にし、新たなIoT脅威への対応を加速する統一的で体系的な分類法を確立すること。

提案手法

  • IoTスタックのデバイス、インfra構造、通信、サービスレイヤーに脅威をマッピングする4レイヤー攻撃分類法を構築した。
  • 消費者、商業、産業分野から9件の事実上のIoTサイバーインシデントを収集・分析し、攻撃チェーンと根本的脆弱性を抽出した。
  • 各インシデントを提案された分類法にマッピングすることで、レイヤー固有の攻撃パターンと影響ベクトルを示した。
  • すべてのセクターに共通する脆弱性として、デフォルト認証情報、暗号化されていない通信、ネットワークセグメンテーションの欠如を同定した。
  • インシデント分析に基づき、セキュア・バイ・デザインの原則、プロトコルの強化、ネットワークセグメンテーションなどの的を絞った緩和戦略を提案した。
  • 先行研究および業界実務の知見を統合し、包括的なIoTセキュリティのための政策的・技術的フレームワークを提言した。
Figure 1: Overview of commercial, consumer, and industrial Internet of Things (IoT) sectors.
Figure 1: Overview of commercial, consumer, and industrial Internet of Things (IoT) sectors.

実験結果

リサーチクエスチョン

  • RQ1消費者、商業、産業の文脈におけるIoTアーキテクチャの異なるレイヤーにわたり、IoT攻撃を体系的に分類する方法は何か?
  • RQ23つの主要なIoTセクターにおいて、事実上のIoT攻撃で最も一般的に悪用された脆弱性は何か?
  • RQ3消費者、商業、産業用IoT環境における攻撃チェーンと利用手法はどのように異なるか?
  • RQ4このような攻撃を防止または緩和するための最も効果的な技術的および政策的対策は何か?
  • RQ5デフォルト認証情報や暗号化されていないデータ送信といった共通の脆弱性が、多様なIoTエコシステムにわたって継続して存在する程度はどの程度か?

主な発見

  • 本研究では、2020年のモバイルおよび無線ネットワーク攻撃の30%がIoTデバイスを含んでおり、その脅威プロファイルが高まっていることを明らかにした。
  • Bluetooth Low Energy(BLE)プロトコルは、平文での送信および不適切なペアリングメカニズムにより、データ漏洩および認証バイパス攻撃に対して脆弱であることが判明した。
  • デフォルト認証情報とネットワークセグメンテーションの欠如は、消費者、商業、産業用IoTシステムで繰り返し発生する脆弱性であった。
  • 事実上のインシデントは、損傷を受ける医療機器や産業制御システムが、深刻な安全上の問題や運用の停止を引き起こす可能性があることを示した。
  • 提案された攻撃分類法により、脅威をレイヤーごとに体系的に分類でき、個々の攻撃に対する臨時の分析の必要性が低下した。
  • 技術的強化と規制の強化を組み合わせた、政策を基盤とする統一的アプローチが、多様なエコシステムにおけるIoTセキュリティの向上に不可欠である。
Figure 2: A tree diagram of attacks and threats on Internet of Things (IoT) and cyber-physical systems (CPS) [ 18 ] .
Figure 2: A tree diagram of attacks and threats on Internet of Things (IoT) and cyber-physical systems (CPS) [ 18 ] .

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。