Security in a completely interconnected world

James Joseph Clarke, Stefanos Gritzalis, Jianying Zhou, Rodrigo Román · Security and Communication Networks · 2014

The convergence of multiple paradigms, visions, and technologies – Internet of Things (IoT) and Web of Things (WoT); Ambient Intelligence (AmI); Machine-to-Machine (M2M); and many others – is giving birth to a world of interconnected things. A world where any entity (be it a machine, an object, a person, or anything) can collaborate with each other, anytime and anywhere, in the provisioning of services. This concept of a truly interconnected world is at its infancy, yet there are various commercial players pushing previously envisioned services to the real world: from centralized Big Data repositories to “intranet of things” systems, from industrial information services to personal wearable sensor systems. Moreover, this evolution does not stop here, as the scientific community is constantly researching new advances in this area. Additionally, there is a factor that must not be overlooked in the development of this interconnected world: security. To truly understand the importance of this factor, we just need to check the state of another interconnected infrastructure: the current Internet. While functional and resilient, the current Internet is still a target of malicious attacks that affect both its users and its infrastructure. However, the scope of a truly interconnected world goes well beyond the current Internet: encompassing a global interoperable connectivity and accessibility by a myriad of heterogeneous entities, with countless data streams that can be aggregated and processed when necessary. Without the proper fault-tolerant security mechanisms, all this wealth of services and information might be not only accessed by users but also manipulated by malicious attackers. Precisely, due to the existence of such information flows, we also cannot let privacy go unnoticed in the development of security solutions for this particular context. Not only are the personal data of users at stake (e.g. daily life, medical records, private information), but also the confidential information managed by larger entities. Consequently, the purpose of this special issue is to introduce six research articles that study how to protect users and devices in the context of an interconnected world, with a special emphasis on privacy-preserving solutions. The contributions of these papers are outlined in the succeeding text. The privacy challenges are not only daunting, but also uncharted. Who are the stakeholders? What concrete threats exist, and how can they be defined? What is the impact of these threats? How can the stakeholders react against these threats? The goal of the article entitled “Privacy in the Internet of Things: Threats and Challenges”, by Ziegeldorf, Garcia-Monchon, and Wehrle, is to provide detailed answers to all these questions. Note that, even if the article focuses specifically on the Internet of Things, most of its analysis can be applied to all the other paradigms that compose this interconnected vision – as they share various underlying principles such as heterogeneous connectivity. In an interconnected world, it is essential for the devices to route the information to each other. One possible solution, which has been studied for years in the area of big distributed infrastructures, are P2P overlay networks. Still, there are several challenges in this area, such as how to manage the users’ identities while preserving their anonymity, and the existence of various attacks that can manipulate how identities are assigned (e.g. Sybil, Eclipse, MITM). The purpose of the paper entitled “RIAPPA: a Robust Identity Assignment Protocol for P2P overlays”, by Caubet et al., is to provide a generic, not algorithm-dependant protocol that can deal with these challenges. In the exchange of information between things, it is not only important to provide anonymity when necessary, but also to maintain a certain Quality of Service (QoS) to avoid excessive service degradation. The goal of the paper entitled “On Collaborative Anonymous Communications in Lossy Networks”, by Rebollo-Monedero et al., is to introduce a Crowds-like protocol for anonymous communication that establishes quantifiable metrics of anonymity and QoS. Such metrics enable the authors to perform a detailed mathematical analysis of the protocol, effectively improving the scope of the original Crowds protocol while achieving a reasonable balance between anonymity and QoS. In fact, due to the importance of maintaining a reasonable QoS while applying the security protocols, this special issue includes the paper entitled “Analysis and Taxonomy of Security/QoS tradeoff solutions for the Future Internet”, by Nieto and Lopez. This paper provides a thorough analysis of the coexistence of security and QoS mechanisms within the context of Future Internet scenarios. The paper analyses existing solutions and identifies potential problems, and also describes the major pitfalls in the integration of existing networking models such as Wireless Sensor Networks (WSN) and Cellular networks. Most of the previous papers focus on anonymity. But there are other privacy issues that must be taken into vaccount. For example, by continuously querying the network about several topics, users can be profiled – which in some cases might reveal bits of information even more important and private than our identities. The paper entitled “Enhancing Information Lookup Privacy through Homomorphic Encryption”, by Fotiou et al., provides a broker-based solution to this problem. Such a solution is also optimized, achieving a balance between the complexity of the computations and the communication overhead between the involved parties. Finally, if the networked embedded systems that comprise our interconnected world are not properly designed to comply with various security properties, attackers will surely find their way to break into them – no matter what security and privacy protocols are developed. The article entitled “Integrating security mechanisms into embedded systems by domain-specific modeling”, by Vasilevskaya et al., combine security and software engineering solutions (e.g. Model-based development (MBD), information security ontology) in order to allow system designers to easily integrate security requirements during the design process. We would like to express our gratitude to Professor Hsiao-Hwa Chen and Professor Hamid R. Sharif, Editors-in-Chief of the Security and Communication Networks journal, for their support before and during the development of this special issue. We would also like to thank the authors that chose to publish their research findings in this special issue, as a truly interconnected world is within our grasp – but we must find ways to protect it before it becomes a liability rather than a blessing. Finally, we would like to thank all the reviewers that, with their time, efforts, and their comments, helped the authors to strengthen their security protocols and mechanisms.

Read the paper · More papers on PaperTik