[论文解读] Threats and Corrective Measures for IoT Security with Observance of Cybercrime: A Survey
本综述识别了物联网在各架构层级中的关键安全威胁,并提出了相应的纠正措施,强调物联网取证以及人工智能、区块链和边缘计算等新兴技术在网络犯罪调查中的应用。该研究为保障物联网系统安全提供了全面的框架,并探讨了智能环境中数字取证的开放性挑战。
Internet of Things (IoT) is the utmost assuring framework to facilitate human life with quality and comfort. IoT has contributed significantly to numerous application areas. The stormy expansion of smart devices and their credence for data transfer using wireless mechanics boosts their susceptibility to cyber-attacks. Consequently, the rate of cybercrime is increasing day by day. Hence, the study of IoT security threats and possible corrective measures can benefit the researchers to identify appropriate solutions to deal with various challenges in cybercrime investigation. IoT forensics plays a vital role in cybercrime investigations. This review paper presents an overview of the IoT framework consisting of IoT architecture, protocols, and technologies. Various security issues at each layer and corrective measures are also discussed in detail. This paper also presents the role of IoT forensics in cybercrime investigation in various domains like smart homes, smart cities, automated vehicles, healthcare, etc. Along with the role of advanced technologies like Artificial Intelligence, Machine Learning, Cloud computing, Edge computing, Fog computing, and Blockchain technology in cybercrime investigation are also discussed. At last, various open research challenges in IoT to assist cybercrime investigation are explained, which provide a new direction for further research.
研究动机与目标
- 分析物联网架构在应用层、网络层和数据处理层中的安全漏洞。
- 识别由无线互联设备快速部署所驱动的物联网生态系统中的关键威胁。
- 研究物联网取证在智能家居、医疗保健和智慧城市等各领域网络犯罪调查中的作用。
- 评估先进技术(如人工智能、机器学习、云计算、边缘计算、雾计算和区块链)在提升网络犯罪调查与数字取证方面的潜力。
- 突出物联网安全与取证领域中阻碍有效网络犯罪调查的开放性研究挑战,以指导未来的研究方向。
提出的方法
- 对物联网协议栈中应用层、网络层和数据层的物联网安全威胁进行系统性综述。
- 分析物联网中现有协议和技术(如MQTT、CoAP和6LoWPAN)中固有的漏洞。
- 将取证方法论整合到物联网系统中,以支持数字证据收集和证据保管链程序。
- 评估人工智能和机器学习在物联网环境中异常检测与威胁预测中的作用。
- 评估边缘计算和雾计算在降低延迟、提升实时取证分析效率方面的作用。
- 探索区块链在保障物联网取证中审计日志安全与数据完整性方面的潜力。
实验结果
研究问题
- RQ1物联网架构各层的主要安全威胁是什么?它们如何影响系统完整性?
- RQ2物联网取证在智能家居、自动驾驶车辆和医疗系统等现实应用领域中如何有效应用?
- RQ3人工智能、区块链和边缘计算等新兴技术在提升物联网环境中网络犯罪调查方面有哪些作用?
- RQ4从资源受限的物联网设备中收集、保存和分析数字证据面临哪些关键挑战?
- RQ5物联网安全与取证领域中仍存在哪些阻碍有效网络犯罪调查的开放性研究问题?
主要发现
- 使用无线通信的物联网设备迅速普及,扩大了攻击面,使其极易遭受网络攻击。
- 物联网取证对网络犯罪调查至关重要,但受限于设备异构性、存储空间有限以及网络拓扑动态变化等问题。
- 人工智能和机器学习技术在物联网网络中实时检测异常和预测威胁方面展现出良好前景。
- 边缘计算和雾计算通过支持设备端分析,降低延迟并提升取证数据处理效率。
- 区块链技术通过提供防篡改日志,增强了物联网取证中的数据完整性和可审计性。
- 仍存在若干开放挑战,包括取证程序的标准化、证据收集的可扩展性,以及跨多样化物联网平台的互操作性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。