We describe a framework and tool specification that represents a step towards cybersecurity testing and monitoring of IoT ecosystems. We begin with challenges from a previous paper and discuss an integrated approach and tools to enable testing and monitoring to address these challenges. We also describe exemplary use cases of IoT ecosystems and propose approaches to address the challenges using the framework and tools. The current status of this work is that the specification and conceptualisation is complete, use cases are understood with clear challenges and implementation / extension of the tools and framework is underway with tools at different stages of development. Several key observations have been made throughout this work, as follows. 1) Tools may be used in multiple different combinations, and ad-hoc use is also encouraged, where one tool may provide clues and other tools executed to undertake further investigations based on initial results. 2) Automated execution of tool chains is supported by workflows. 3) support for immutable storage of audit records of tests and results is an important requirement. 4) Indicators (observations or measurements representing information of relevance for assessment of cyber security) are a key mechanism for intercommunication between one tool and another, or with the operator. 5) Mapping this work to established security development lifecycles is a useful means of determining applicability and utility of the tools and framework. 6) There is a key interplay between devices and systems. 7) Anomaly detection in multiple forms is a key means of runtime monitoring. 8) Considerable investigation is needed related to the specifics of each device / system as an item of further work.
The Common Vulnerabilities and Exposures (CVE) database lists a large number of vulnerabilities that are present in specific versions of software libraries and applications, but although there is a severity ranking, it does not immediately follow that an identified vulnerability with high severity will be particularly important for a specific application. This paper presents the motivation for CVE Prioritization for a given case and describes an outline process for evaluating the priority of CVEs via risk assessment simulations.
Resilience and Survivability in networks is an area which is growing fast, mainly due to the fact that these vital desired properties for a network, protocol, application, or service behaviour, are now receiving a lot of attention from industry, research, academia, and standardization groups-thanks to the emergence of autonomic & cognitive management and control paradigms for the evolving networks in recent years. In characterizing the resilience properties of a system or individual functional entities of a system, the area of autonomics is extending the traditional scope and meaning of resilience in networks, by including self-diagnosing and self-repairing/self-healing behaviours, as well as proactive resilience to various types of challenges i.e. adverse conditions of operation and incidents (including fault-activations and security attacks and threats). This goes beyond the protection and restoration techniques for survivable networks found in protocols such as SDH, ATM, and IP-Fast-Re-route. What is becoming crucial for the global community is the establishment of standardized frameworks that can be applied for implementing interoperable systems that exhibit resilience properties in their own capacity and collaboratively as networked systems. This paper reports on a recently launched initiative in ETSI (European Telecommunications Standards Institute) that is aimed at standardizing resilience, survivability, autonomic fault-management and autonomic security management. We outline the types of concepts and architectural principles that are standardizable from resilience, survivability, and autonomic fault and security management point of view. We present and discuss a candidate evolvable architectural framework for standardization that unifies resilience, survivability and autonomic fault-management within a single holistic framework. It unifies the aspects by defining the responsible Functional Blocks (FBs) and their interworking in the realization of resilience, survivability, autonomic fault-management and autonomic security management in systems and networks. We show how research results in these areas can now be contributed to developing and relying on a commonly-shared (i.e. common baseline) unified standardized framework, by adopting, enhancing and evolving the framework presented in this paper as standardization activity (open to all technical experts/researchers to now join).
In the vision of both researchers and standardization committees, networks and services will evolve in the direction of increasing pervasiveness, convergence, and quality of service management capability. Consequently, users will gain an increasing dependency on the presence and availability of network connectivity and the huge plethora of provided services. Yet fostering the development of our society, such dependency on a relatively young technology poses serious threats, especially from the trustworthiness, security and privacy point of view. In this paper, we will describe and critically evaluate user behavior clustering aimed at monitoring and assuring the security of NGN-based applications. Different models of user behavior, developed within both ISP and academic research projects will be described, and several techniques for manipulating and exploiting such model for the anomaly detection purpose will be described and evaluated.
ENUM (telephone number mapping) is a key enabler in the convergence between IP-based networks and the traditional PSTNs that may result in additional complexity in commercial relationships and regulation of the telecommunications sector. In particular, the current ENUM may significantly increase the risk of unscrupulous use of the information managed (e.g., public user identifiers and user/service reachability). The aim of this article is to describe a new functional reference model for ENUM, and provide some new requirements that enable user privacy and security.
The paper describes the limits of the current ENUM system from the security point of view, identifies the main security threats and proposes a new framework that addresses such issues. As a matter of fact, those issues could limit the full deployment of ENUM and hence limit also the transition to the IP world of the TELCO services. The paper proposes a new framework called "Secure ENUM" that enhances the current ENUM by adding a Policy Management system to allow the control of resolution of E.164 number (1).
Alessandro Basso合作论文数University of Torino Computer Science Department c.so Svizzera 185 10149 Torino Italy1