Forensics is a science that deals with using scientific principles in order to aid an investigation of a civil or criminal crime. It is a system of procedures that allow an investigator to use as much resources as possible in order to come up with a conclusion for an investigation. Since forensics is a very general term that encompasses an investigation process using scientific knowledge, one can separate a system of investigation based on how it is conducted. This chapter introduces of internet of things (IoT) forensics, IoT application in forensics field. Art-of-states for IoT forensics are provided. The issues for IoT forensics are identified. Also, we have introduced the proposed data classification in Iot forensics protocol. At the end of this chapter, we point out a brief summary and conclusion.
With IoT era, development raises several significant research questions in terms of system architecture, design and improvement. For example; the requirement of virtual resource utilization and storage capacity necessitates making IoT applications smarter; therefore, integrate the IoT concept with cloud computing will play an important role. This is crucial because of very large amounts of data that IoT is expected to generate. The Cloud of Things (CoT) is used to connect heterogeneous physical things to the virtual domain of the cloud. Despite its numerous advantages, there are many research challenges with utilization of CoT that needs additional consideration. These include high complexity, efficiency, improving reliability, and security. This chapter introduces CoT, its features, the applications that use CoT. CoT, like all other networked functions, is vulnerable to security attacks. The security risks for CoT are listed and described. The security requirements for CoT are identified and solutions are proposed to address the various attacks on CoT and its components.
The emergence of the Internet of Things (IoT) is expected to significantly advance the technology development in many application domains such as agriculture, home automation, and healthcare. However, in the IoT era, this development faces serious research challenges in terms of handling large amounts of data, designing efficient system architectures, and implementing appropriate mechanisms for privacy and security assurance. Especially the network security aspect of the IoT is of major importance due to huge amounts of data that the IoT is expected to generate and handle, and considering the limited resources of typical IoT devices. One of the serious security threats are the physical attacks on the IoT devices that operate in remote locations. These are known in the literature as the node capture attacks. Motivated by the aforementioned issues, this paper first introduces the background of IoT security and discusses the related challenges. Next, a secure group communication scheme that enables IoT using low energy wireless IP network is described. The proposed approach is based on Shamir’s Secret Sharing scheme, which has been enhanced to enable secure group-to-group communication of resource-constrained IoT devices. In particular, we consider the low energy wireless IP networking technology as one of the IoT enablers and the problem of mitigating the negative effects of node capture attacks on IoT devices. Simulation results show significant improvements of the proposed scheme over the traditional public-key based approach.
Following the rapid development of the Internet of Things (IoT) technology worldwide, the integration of the IoT to the cloud, referred to as the Cloud of Things (CoT), has become essential for easy access and management of remote resources. However, security and malicious intrusions must be seriously considered to ensure network reliability and data confidentiality. In this paper, the authors analyze the security implications of CoT and propose a solution for data confidentiality. They prove that the proposed solution can effectively protect against a number of security attacks.
Diffie-Hellman (DH) key exchange is a well known method for secure exchange of cryptographic keys and has been widely used in popular Internet protocols, such as IPsec, TLS, and SSH. To enable authenticated key establishment, the DH protocol has been integrated with the digital signature algorithm (DSA). In this paper, we analyze three variants of the integrated DH-DSA protocol. We study the protocol variants with respect to known types of attacks and security features. In particular, the focus is on the properties of forward secrecy, known-key security, and replay attack resilience.
Over the last decade, Internet of Things (IoTs) have brought radical changes to the means and forms of communication for monitoring and control of a large number of applications including Smart Grid (SG). Traditional energy networks have been modernized to SGs to boost the energy industry in the context of efficient and effective power management, performance, real-time control and information flow using two-way communication between utility provides and end-users. However, integrating two-way communication in SG comes at the cost of cyber security vulnerabilities and challenges. In the context of SG, node compromise is a severe security threat due to the fact that a compromised node can significantly impact the operations and security of the SG network. Therefore, in this chapter, Key Management Scheme for Communication Layer in the Smart Grid (KMS-CL-SG) has proposed. In order to achieve a secure end-to-end communication we assign a unique key to each node in the group.
A smart grid is a well-thought-out smart network of meta-systems and subsystems that aims at improving the efficiency the traditional power grid and at ensuring reliable energy delivery. To achieve its goals, a smart grid requires a two-way communication between the utility provider and the end user. One way to achive that is by incorporating the wireless sensor network (WSN) technology into smart grids. A WSN-based smart grid network can bridges virtual and the physical worlds by exploiting the sensing and computing capabilities of smart meters. In particular, a WSN based smart grid comprises numerous small sensing nodes that can sense, read variables from their ambiance, and wirelessly report the readings to each other. Because of cost constraints and miniaturization requirements, these nodes have limitations in terms of available power and computational resources. The resulting resource scarcity imposes new challenges in terms of network and data security, that need to be thoroughly addressed. Hence, the purpose of this paper is to present the current security challenges and attack vectors on WSNs in smart grids and to analyze the existing security solutions.
A Smart Grid (SG) is a modern electricity supply system. It uses information and communication technology (ICT) to run, monitor and control data between the generation source and the end user. It comprises a set of technologies that uses sensing, embedded processing and digital communications to intelligently control and monitor an electricity grid with improved reliability, security, and efficiency. SGs are classified as Critical Infrastructures. In the recent past, there have been cyber-attacks on SGs causing substantial damage and loss of services. A recent cyber-attack on Ukraine's SG caused over 2.3 million homes to be without power for around six hours. Apart from the loss of services, some portions of the SG are yet to be operational, due to the damage caused. SGs also face security challenges such as confidentiality, availability, fault tolerance, privacy, and other security issues. Communication and networking technologies integrated into the SG require new and existing security vulnerabilities to be thoroughly investigated. Key management is one of the most important security requirements to achieve data confidentiality and integrity in a SG system. It is not practical to design a single key management scheme/framework for all systems, actors and segments in the smart grid, since the security requirements of various sub-systems in the SG vary. We address two specific sub-systems categorised by the network connectivity layer – the Home Area Network (HAN) and the Neighbourhood Area Network (NAN). Currently, several security schemes and key management solutions for SGs have been proposed. However, these solutions lack better security for preventing common cyber-attacks such as node capture attack, replay attack and Sybil attack. We propose a cryptographic key management scheme that takes into account the differences in the HAN and NAN segments of the SG with respect to topology, authentication and forwarding of data. The scheme complies with the overall performance requirements of the smart grid. The proposed scheme uses group key management and group authentication in order to address end-to-end security for the HAN and NAN scenarios in a smart grid, which fulfils data confidentiality, integrity and scalability requirements. The security scheme is implemented in a multi-hop sensor network using TelosB motes and ZigBee OPNET simulation model. In addition, replay attack, Sybil attack and node capture attack scenarios have been implemented and evaluated in a NAN scenario. Evaluation results show that the scheme is resilient against node capture attacks and replay attacks. Smart Meters in a NAN are able to authenticate themselves in a group rather than authenticating one at a time. This significant improvement over existing schemes is discussed with comparisons with other security schemes.
A Neighbourhood Area Network is a functional component of the Smart Grid that interconnects the end user domain with the Energy Services Provider (ESP) domain. It forms the “edge” of the provider network, interconnecting homes instrumented with Smart Meters (SM) with the ESP. The SM is a dual interface, wireless communication device through which information is transacted across the user (a home) and ESP domains. The security risk to the ESP increases since the components within the home, interconnected to the ESP via the SM, are not managed by the ESP. Secure operation of the SM is a necessary requirement. The SM should be resilient to attacks, which might be targeted either directly or via the network in the home. This paper presents and discusses a security scheme for groups of SMs in a Neighbourhood Area Network that enable entire groups to authenticate themselves, rather than one at a time. The results show that a significant improvement in terms of resilience against node capture attacks, replay attacks, confidentiality, authentication for groups of SMs in a NAN that enable entire groups to authenticate themselves, rather than one at a time.
Advanced Metering Infrastructure (AMI) has currently become the most popular element in smart grid implementations both in home area network (HAN) and Neighborhood Area Network (NAN) environment as well as in large commercial/industrial establishments. The security of AMI has been an issue for several years, and many tools and utilities have been proposed to ensure the security of AMI networks. However, no network is completely safe from malicious users (hackers). Smart Meters (SM) in the NAN are typical targets for attackers, their objective being the acquisition of authentication information and attempting to successfully authenticate to become a part of the NAN. Such attacks are easy to launch and can cause significant impact since false data can be injected into the system. We explore the impact of such an attack on a previously developed authentication scheme and demonstrate that packet replays at a very fast rate can drain resources in a fashion similar to a Denial of Service (DoS) attack. The effect is pronounced since the authentication scheme uses a multi-hop path to reach the central authentication server. The intermediate nodes partially process each packet before forwarding it, causing an increase in the end-to-end delays as well as increased energy consumption. The authentication scheme is coded in C and the replay attacks are launched using an existing open source security tools.
A Smart grid is a modern electricity delivery system. It is an integration of energy systems and other necessary elements including traditional upgrades and new grid technologies with renewable generation and increased consumer storage. It uses information and communication technology (ICT) to operate, monitor and control data between the generation source and the end user. Smart grids have duplex power flow and communication to achieve high efficiency, reliability, environmental, economics, security and safety standards. However, along with unique facilities, smart grids face security challenges such as access control, connectivity, fault tolerance, privacy, and other security issues. Cyber-attacks, in the recent past, on critical infrastructure including smart grids have highlighted security as a major requirement for smart grids. Therefore, cryptography and key management are necessary for smart grids to become secure and realizable. Key management schemes are processes of key organizational frameworks, distribution, generation, refresh and key storage policies. Currently, several secure schemes, related to key management for smart grid have been proposed to achieve end-to-end secure communication. This paper presents a comprehensive survey and discussion on the current state of the key management of smart grids.
A smart grid is a power system that uses information and communication technology to operate, monitor, and control data flows between the power generating source and the end user. It aims at high efficiency, reliability, and sustainability of the electricity supply process that is provided by the utility centre and is distributed from generation stations to clients. To this end, energy-efficient multicast communication is an important requirement to serve a group of residents in a neighbourhood. However, the multicast routing introduces new challenges in terms of secure operation of the smart grid and user privacy. In this paper, after having analysed the security threats for multicast-enabled smart grids, we propose a novel multicast routing protocol that is both sufficiently secure and energy efficient.We also evaluate the performance of the proposed protocol by means of computer simulations, in terms of its energy-efficient operation.
Smart grid (SG) comprises a set of technologies that uses sensing, embedded processing and digital communications to intelligently control and monitor an electricity grid with improved reliability, security, and efficiency. However, its reliance on traditional IT principles presents a new attack vector for security threats and vulnerabilities. Key management is a fundamental requirement for security implementation in SG. However, it is not practical to design a single key management scheme/framework for all systems, parties and segments in the SG, since it is necessary to consider the security requirements of various sub-systems in the SG and design the security for the specific sub-system. In this paper, we propose a new cryptographic key management scheme that takes into account the different security and performance requirements. We address two specific sub-systems categorized by the network connectivity – the Home Area Network (HAN) and the Neighborhood Area Network (NAN). The schemes provides secure communication and are shown to be resilient to attack types that are classified as Denial-of-Service, Man-in-the-middle, Replay and Sybil attacks by a security analysis. Attack detection on individual devices to take reactive action is work in progress. Key-Words: Smart grid, Security in smart grid, Key Management; Sybil Attack
—Named Data Networking (NDN) is a novel networking approach that aims at overcoming some of the limitations of the current Internet. In particular, NDN aims at providing better privacy and security by focusing on the data items themselves rather than on the location of data. This is achieved by using soft states at the routers, which record the requests/interests for data from users in the Pending Interest Table (PIT). However, this new networking concept opens up avenues for launching Distributed Denial-of-Service (DDoS) attacks on PITs. That is, an attacker may flood the network with a large number of Interest packets that would overflow the PITs at the routers, thus preventing legitimate users from receiving the requested data. This type of DDoS attack is known as the Interest Flooding Attack (IFA) and, if not adequately dealt with, may severely disrupt the normal operation of an NDN system. In this paper, we first show that the basic NDN mechanism is vulnerable to IFA even when the attacker has very limited resources. Next, we propose a mitigation technique that allows routers to quickly identify and block such DDoS attempts, by detecting anomalous user behaviour. We also introduce an additional security layer by using public-key based router authentication. We evaluate our proposed scheme by means of computer simulations and show that a sufficient level of security can be achieved with little processing and storage overhead.
A smart grid is a power system that consists of communication infrastructure, IT systems, advanced actuators, and advanced monitoring building blocks for a smart city. The devices powered in smart homes have embedded systems in appliances. They are sensor-based and network-enabled and commonly referred to as Internet of Things (IoT). A Cloud of Things (CoT) virtualizes the IoT and provides monitoring and control. The CoT services in the home area network will enable a collection of applications that will use real-time data from these appliances. As always, security and privacy issues are prime since it involves private data from the home. In this paper, we propose a secure scheme for Home Area Network (HAN) based on CoT. The security scheme discusses how a device that is connected at a home is serviced from the CoT. Specifically, it illustrates how the security requirements are administered from the CoT and discusses a specific scheme for key management for the HAN.
Many systems and technologies are involved with smart housing including communication technology, IT systems, actuators, sensors and advanced monitoring building blocks. The devices powering smart homes are systems implanted in appliances that are sensor-based and network-enabled. The possibility of accessing appliances through the Internet is referred to as the Internet of Things (IoT). A Cloud of Things (CoT) virtualizes the IoT and provides monitoring and visualization. The emerging CoT services in smart housing will enable a new generation of systems and intelligent use of a collection of applications that can be accessed in real time. Despite its benefits, CoT may also be subject to some security and privacy issues. In this paper, we propose a secure scheme for a smart house based on CoT. Our scheme defines how a connected home device is serviced from the CoT to bring it into the secure zone of the network operation infrastructure. Specifically, we illustrate how the security requirements are administered from the CoT and discuss a secure scheme for key management for smart housing.