An ISO-Compliant Test Procedure for Technical Risk Analyses of IoT Systems Based on STRIDE

Peter Danielis, Moritz Beckmann, Jan Skodzik · 2020

The rising number of IoT systems deployed in production increases the risk of becoming a victim of costly attacks. The complex architecture of such systems increases their attack surface making the systems more vulnerable by attacks that can even paralyze production. For 2020, it is estimated that more than 30 billion IoT devices are in use worldwide; of which more than 5.8 billion in the industrial sector. It is therefore imperative today to have a threat modeling tool that examines all system components and assigns them a risk of being exposed. This paper proposes a novel ISO-compliant test procedure for the technical risk analysis of IoT systems since state-of-the-art methods are either not ISO-compliant or are not suitable for technical risk analyses. It is based on the generic threat model Microsoft STRIDE, which has been developed to consider and evaluate all system components. The test procedure is able to identify vulnerabilities and assigns a risk to them. It complies with ISO/IEC 27001 and implies ISO/IEC 27005 and ISO 31000. The threats are stored in a threat database and linked to countermeasures. The designed tool implementing the novel test procedure automatically proposes countermeasures for certain attacks to the user. The tool uses a learning database in which new insights can be entered during each risk analysis so that the tool is improved with each use. As proof of concept, an IoT system is analyzed for its risks and the high achievable accuracy of the proposed risk assessment is shown.

Read the paper · More papers on PaperTik