Threat Models and Attack Strategies in the Internet of Things
V.M. Sivagami, K. Kiruthika Devi, V. Vidhya, S. Swarna Parvathi · 2024
The Internet of Things (IoT) is revolutionizing our interaction with the world, as it involves a network of data-collecting devices and cloud services designed for data storage and analysis. This data often contains personal or sensitive information, making it susceptible to unauthorized access if not adequately secured. IoT devices have increasingly become targets for sophisticated cyber-attacks, necessitating vigilance in safeguarding assets and customer privacy from these emerging threats. Security in the realm of IoT should be a focal point, with attention directed toward three key areas: (a) Securing Devices – Ensuring that IoT devices themselves are fortified against potential breaches. (b) Establishing Secured Connections and Communications – Implementing robust security measures for the connections and data exchanges between devices and networks. (c) Providing Secured Cloud Services to the Public – Ensuring that cloud services used for data storage and analytics are protected to prevent unauthorized access. A recommended approach to bolster security is to adopt a layered strategy, which incorporates multiple defense mechanisms to thwart hackers effectively. Another challenge in the IoT landscape is the secure transmission of data, as a significant portion of communication lacks encryption. Without a comprehensive threat model, organizations may underestimate the risks associated with aspects such as provisioning, maintenance, device identification, and authentication. Additionally, it’s important to recognize that attacks on IoT vulnerabilities or security lapses within these environments can lead to physical harm and safety-related consequences. The proposed chapter delves into various types of attacks that impact IoT devices and underscores the critical role of threat modeling. It also highlights the challenges faced in this domain and suggests potential directions for future research.