In this paper, we propose a new approach to manage the threats brought by an IoT infrastructure to a legacy information system (IS). We first give a state of art for information security properties in IoT and IS based on standards such as ISO 16982 and ISO 27005 and a previously published taxonomy. Then we detail an innovative method, based on the evaluation of threats brought by an IoT infrastructure onto an IS. It is represented as a qualitative matrix between IoT infrastructure threats and the Security properties of the IS. The method is then applied to the use case of connected light bulbs. Thanks to this approach, it is possible to logically organize threat management while integrating an IoT infrastructure into an IS.
This paper is a first attempt to define a set of security vulnerabilities for the Internet of Things (IoT), in a corporate environment, in order to classify various connected objects based on a taxonomy that was previously proposed. The IoT is a complex infrastructure that we divide in four parts (objects, transport, storage, interfaces). It needs protection and supervision. The object and its ecosystem are surrounded with other devices that can become entry points or targets of attacks, even if they are protected from the outer world but not from their local environment. We study the impact of attacks (such as OS reprogramming that has been recently published) on connected thermostats and their possible consequences on their environment, as a first approach to a threat analysis for the IoT.
The Internet of Things (IoT) has various fields of application including health care, resource management, asset tracking, etc. Depending on the use case, various technologies like RFID, Wireless Sensor Network (WSN) or Smart Objects can be used. With each of these comes a specific vision of what the IoT and connected objects are and -- to our knowledge -- there is no global picture of the IoT. The issue with this approach is that specific problems have been addressed before global ones: what if something has been missed? We propose a definition and taxonomy for connected objects and the IoT.