Editorial for special issue on security, trust, and privacy in internet of things: Challenges and solutions

Weizhi Meng, Piotr Cofta, Tyrone W. A. Grandison · International Journal of Network Management · 2020

The Internet of Things (IoT) generally encompasses everything connected to the Internet, from simple/lightweight sensors to smartphones and wearables, and other embedded systems with connections. By combining these connected devices with automated systems, it becomes feasible to help someone with a particular task, or learn from a process through collecting and analyzing information from different sources. In industry, sensors on product lines can increase efficiency and cut down on waste. One study estimates 35% of U.S. manufacturers are using data from smart sensors within their set-ups already. IoT can make it more efficient in how to do things, save time and money. Gartner report predicts that more than 20.8 billion IoT devices might be widely used by the end of 2020. However, everything that is connected to the Internet could be hacked, and it is the same to IoT applications. Insecure IoT systems are vulnerable to many threats and exploits. The Symantec report has shown that IoT has become a prime target for cyber-criminals to exploit, where the number of IoT attacks increased from about 6,000 in 2016 to 50,000 in 2017, nearly a 600% rise in just one year. Thus, there is a significant need to develop more secure and trusted IoT environments. This special issue of IJNM focuses on how to build trust and hold effective trust management in an IoT environment, and identifies new issues and directions for future research and development work. In the first contribution entitled “Network traffic identification of several open source secure proxy protocols,” Zhang et al. focused on network traffic classification and aimed to investigate both static and dynamic approaches. They examined the cryptographic protocols and the native source code to exploit the potential flaws including Shadowsocks, Gost, VMess, XX-Net, and GoQuiet. Then they performed the dynamic analysis by using the deep learning approach to validate the results and provide an automatic way to identify potential weaknesses. The experimental results indicated that their model can achieve an accuracy of around 95%. In the second contribution entitled “Research on adaptive beacon message broadcasting cycle based on vehicle driving stability,” Zhang et al. introduced an adaptive beacon message broadcasting cycle algorithm to adaptively control the vehicle driving stability, i.e., reducing the broadcasting cycle of unstable vehicles and increasing the broadcasting cycle of stable vehicles. In comparison to the traditional fixed-cycle beacon messages, the proposed adaptive transmission algorithm can effectively reduce the transmission energy consumption and the communication delay and enhance the communication quality. In the third contribution entitled “K-PSO: An improved PSO-based container scheduling algorithm for big data applications,” Liu et al. introduced an improved Kubernetes container scheduling algorithm called Kubernetes-based particle swarm optimization (K-PSO). In the pre-selection stage, they optimized the CPU and memory restriction strategy of the node to the pod. In the optimization stage, they considered the CPU/memory of the node and the characteristic factors of the user application. Their results indicate that the K-PSO algorithm can improve the scheduling by about 20% than other strategies without degrading the computing performance. In the fourth contribution entitled “Privacy-preserving cloud-fog–based traceable road condition monitoring in VANET,” Wang et al. proposed an efficient privacy-preserving cloud-fog–based traceable road condition monitoring scheme by using certificateless aggregate signcryption, in which the vehicle can signcrypt the message and upload it to the roadside unit (RSU), as a fog server. They used a trace authority (TRA) to create pseudonym for vehicles and track the true identity of the vehicle when a wrong road condition information brings trouble. The combined server with cloud and fog can reduce the lag time of serving the end user. In the fifth contribution entitled “Research on scheduling method based on traffic matrix for IoT security,” Cao et al. introduced a dynamic traffic scheduling of server cluster (DTSSC) model, which is built on the SDN to balance the server load in a computation cluster. This model is based on a simple intuition that a newly received request should be handled by the server with the maximal computation resource or should be derived from more basic raw measurements of the computation nodes across the network. Therefore, all the servers' load ratio reaches a similar level, by improving the reliability and scalability of the IoT. In the next contribution entitled “Security and trust preserving inter- and intra-cloud VM migrations,” Aslam et al. extended the secure VM migration solution without compromising the security level and user-defined trust level on the platform by introducing a trust credential called Trust_Token. They used Trusted Platform Module (TPM) capabilities to securely migrate user VM with assurance of its hosting only on trustworthy cloud platforms. They also analyzed the security properties using the Tamarin protocol verification tool and found that it would be safe under the Dolev-Yao adversary model. In the next contribution entitled “A fog-based collaborative intrusion detection framework for smart grid,” Li et al. introduced a fog-based collaborative intrusion detection framework (CIDS) to enhance the detection performance and efficiency in smart grids (SG). A node consists of several key components, including collaboration component, trust management component, IDS component with a detector, a rule database and a normal profile, and P2P communication component. The framework contains four layers: cloud layer, fog layer, CIDS layer, and SG layer. They conducted an experiment in collaboration with a grid service provider and an IT company. The results demonstrated that the framework can improve the detection efficiency ranged from 21% to 39% and from 24% to 43% for two internal attack scenarios and from 29% to 45% for external attack scenario, respectively. In the last contribution entitled “Secure grid-based density peaks clustering on hybrid cloud for industrial IoT,” Sun et al. introduced a secure grid-based density peaks clustering algorithm (SGBDPC) on a hybrid cloud for IIoT big data using grids to lower density samples and quickly find cluster centers. The client encrypts the private data using the homomorphic encryption scheme and then uploads the ciphertext to the cloud service side. The evaluation on four datasets demonstrated the accuracy and efficiency. On the whole, the special issue papers cover a broad range of research on security, privacy, and trust on IoT and discuss various security threats and potential solutions. The team of guest editors would like to thank Editor-in-Chief James Won-Ki Hong and Associate Editor-in-Chief Lisandro Zambenedetti Granville for their great support, as well as the paper authors and the reviewers for their contributions. Data sharing not applicable to this article as no datasets were generated or analyzed during the current study.

Read the paper · More papers on PaperTik