Skip to main content
QUICK REVIEW

[论文解读] An Overview of Cyber Threats, Attacks, and Countermeasures on the Primary Domains of Smart Cities

Vasiliki Demertzi, Stavros Demertzis|arXiv (Cornell University)|Jul 10, 2022
Smart Cities and Technologies被引用 9
一句话总结

本文通过综合最新研究成果,对智慧城市七大核心领域——智慧政府、交通出行、环境、生活、医疗、经济和人群——的网络威胁、攻击手段及应对措施进行了全面分析。研究发现,由于缺乏标准化的数据流建模,存在关键的网络安全漏洞,并呼吁采取协调一致、面向各领域的安全措施,以保护公民隐私和日益互联的城市基础设施的完整性。

ABSTRACT

A smart city is a place where existing facilities and services are enhanced by digital technology to benefit people and companies. The most critical infrastructures in this city are interconnected. Increased data exchange across municipal domains aims to manage the essential assets, leading to more automation in city governance and optimization of the dynamic offered services. However, no clear guideline or standard exists for modeling these data flows. As a result, operators, municipalities, policymakers, manufac-turers, solution providers, and vendors are forced to accept systems with limited scalability and varying needs. Nonetheless, it is critical to raise awareness about smart city cybersecurity and implement suitable measures to safeguard citizens' privacy and security because the cyber threats seem to be well-organized, diverse, and sophisticated. This study aims to present an overview of cyber threats, attacks, and countermeasures on the primary domains of smart cities (smart government, smart mobility, smart environment, smart living, smart healthcare, smart economy, and smart people) to present information extracted from state-of-the-art to policymakers to perceive the critical situation and, at the same time, to be a valuable resource for the scientific community.

研究动机与目标

  • 解决智慧城市基础设施中缺乏标准化数据流建模指南的问题。
  • 提高政策制定者和利益相关方对智慧城市中网络威胁日益复杂和高超的认识。
  • 为研究人员和实践者提供面向各领域的网络威胁与应对措施的结构化概览。
  • 通过基于证据的建议,支持可扩展、安全且保护隐私的智慧城市系统的发展。
  • 为科学界提供当前关键智慧城市领域中网络风险的基准参考。

提出的方法

  • 对智慧城市环境中网络威胁的最新文献进行系统性综述。
  • 基于七个主要智慧城市领域(智慧政府、交通出行、环境、生活、医疗、经济和人群)对网络威胁和攻击进行分类。
  • 在每个领域内识别并分类攻击向量、威胁参与者和系统脆弱性。
  • 分析现有应对措施,包括加密、访问控制、入侵检测以及政策框架。
  • 将威胁类型映射到特定基础设施组件和数据流,以突出关键攻击面。
  • 将研究发现整合为统一的框架,用于面向各领域的网络风险评估与缓解。

实验结果

研究问题

  • RQ1针对智慧城市核心领域的网络威胁中,哪些是最普遍且持续演变的?
  • RQ2网络攻击如何利用智慧城市基础设施组件之间的相互依赖性和数据流?
  • RQ3在缓解特定领域网络风险方面,最有效的技术与政策应对措施是什么?
  • RQ4当前智慧城市系统因缺乏标准化数据流模型,在可扩展性和安全性方面存在哪些不足?
  • RQ5政策制定者和城市运营商应如何提升智慧城市环境中网络韧性?

主要发现

  • 智慧城市各领域间缺乏标准化的数据流建模,导致安全态势不一致,系统可扩展性降低。
  • 智慧城市中的网络威胁正变得日益组织化、多样化且复杂,针对关键基础设施造成高影响。
  • 每个主要领域(如智慧医疗和智慧交通)都面临独特的威胁特征,包括数据泄露、服务中断和勒索软件攻击。
  • 访问控制、加密和入侵检测系统等应对措施虽有效,但因治理碎片化而实施不足。
  • 整合隐私保护技术与跨领域安全政策,对于保护公民数据和系统完整性至关重要。
  • 政策制定者和城市运营商需要采取协调一致、基于证据的策略来应对网络风险,尤其是在相互关联的城市生态系统中。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。