Risk Assessment of Cybersecurity IoT Anomalies Through Cyber Value at Risk (CVaR)
Prashant Vajpayee, Gahangir Hossain · 2024
IoT systems, comprising interconnected devices like cameras, sensors, and manufacturing equipment, bring benefits such as enhanced efficiency and safety, but they’re also vulnerable to security threats like data theft and operational disruptions. Existing security assessment frameworks often struggle with IoT complexities. This paper proposes an anomaly-based method tailored for IoT, using anomaly scores, asset valuation, and controls to identify risks and offer mitigation suggestions. Various cyber-attacks, from malware to denial of service, pose significant harm if left undetected. Effective detection relies on diverse machine learning techniques. Identifying high anomaly scores is crucial for informed decision-making. Cyber-Value-at-Risk (CVaR) helps to calculate overall asset risk due to cyber-attacks. The paper suggests a method to assess average risk for assets vulnerable to severe attacks, emphasizing the need for prompt action. In conclusion, this paper presents a tailored approach to assess security risks in IoT systems, focusing on anomaly detection, asset valuation, and risk quantification to strengthen IoT resilience against evolving threats.