SIoT framework: Towards an approach for early identification of security requirements for internet-of-things applications

被引:0
|
作者
Jabangwe R. [1 ,2 ]
Nguyen-Duc A. [3 ]
机构
[1] Maersk Mc-Kinney Moller Institute, University of Southern Denmark, Software Engineering
[2] School of Business, University of South Eastern Norway, Department of Business, IT
来源
关键词
Internet-of-things; Requirement Engineering; Security Framework; Security requirement; Software Engineering;
D O I
10.37190/E-INF200103
中图分类号
学科分类号
摘要
Background: Security has become more of a concern with the wide deployment of Internet-of-things (IoT) devices. The importance of addressing security risks early in the development lifecycle before pushing to market cannot be over emphasized. Aim: To this end, we propose a conceptual framework to help with identifying security concerns early in the product development lifecycle for Internet-of-things, that we refer to as SIoT (Security for Internet-of-Things). Method: The framework adopts well known security engineering approaches and best practices, and systematically builds on existing research work on IoT architecture. Results: Practitioners at a Norwegian start-up company evaluated the framework and found it useful as a foundation for addressing critical security concerns for IoT applications early in the development lifecycle. The output from using the framework can be a checklist that can be used as input during security requirements engineering activities for IoT applications. Conclusions: However, security is a multi-faced concept; therefore, users of the SIoT framework should not view the framework as a panacea to all security threats. The framework may need to be refined in the future, particularly to improve its completeness to cover various IoT contexts. © 2020 Wroclaw University of Science and Technology. All rights reserved.
引用
收藏
页码:77 / 95
页数:18
相关论文
共 50 条
  • [21] An Efficient Framework for Security of Internet-of-Things Devices against Malicious Software Updates
    Qureshi, Anam
    Shamsi, Jawwad
    Marvi, Murk
    JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS, 2024, 2024
  • [22] Towards Security on Internet of Things: Applications and Challenges in Technology
    Sadique, Kazi Masum
    Rahmani, Rahim
    Johannesson, Paul
    9TH INTERNATIONAL CONFERENCE ON EMERGING UBIQUITOUS SYSTEMS AND PERVASIVE NETWORKS (EUSPN-2018) / 8TH INTERNATIONAL CONFERENCE ON CURRENT AND FUTURE TRENDS OF INFORMATION AND COMMUNICATION TECHNOLOGIES IN HEALTHCARE (ICTH-2018), 2018, 141 : 199 - 206
  • [23] Evaluation of a Hybrid Architecture for Security in Internet-of-Things
    Vulpe, Alexandru
    Arseni, Stefan-Ciprian
    Fratu, Octavian
    Halunga, Simona
    2018 21ST INTERNATIONAL SYMPOSIUM ON WIRELESS PERSONAL MULTIMEDIA COMMUNICATIONS (WPMC), 2018, : 516 - 520
  • [24] Learning Internet-of-Things Security "Hands-On"
    Kolias, Constantinos
    Stavrou, Angelos
    Voas, Jeffrey
    Bojanova, Irena
    Kuhn, Richard
    IEEE SECURITY & PRIVACY, 2016, 14 (01) : 37 - 46
  • [25] INTERNET-OF-THINGS: GENESIS, CHALLENGES AND APPLICATIONS
    Matta, Priya
    Pant, Bhasker
    JOURNAL OF ENGINEERING SCIENCE AND TECHNOLOGY, 2019, 14 (03) : 1717 - 1750
  • [26] Internet-of-Things Security and Vulnerabilities: Case Study
    Alqarawi, Ghaida
    Alkhalifah, Bashayer
    Alharbi, Najla
    El Khediri, Salim
    JOURNAL OF APPLIED SECURITY RESEARCH, 2023, 18 (03) : 559 - 575
  • [27] A Survey on Security and Privacy Issues in Internet-of-Things
    Yang, Yuchen
    Wu, Longfei
    Yin, Guisheng
    Li, Lijie
    Zhao, Hongbin
    IEEE INTERNET OF THINGS JOURNAL, 2017, 4 (05): : 1250 - 1258
  • [28] SECURITY AND PRIVACY CONCERNS IN INTERNET-OF-THINGS - A SURVEY
    Chetna
    Mankiran
    Kataria, Ankita
    Kaur, Anmoldeep
    ADVANCES AND APPLICATIONS IN MATHEMATICAL SCIENCES, 2020, 19 (06): : 435 - 442
  • [29] Internet-of-Things Security : Denial of Service Attacks
    Aris, Ahmet
    Oktug, Sema F.
    Yalcin, Siddika Berna Ors
    2015 23RD SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2015, : 903 - 906
  • [30] A Security Requirements Library for the Development of Internet of Things (IoT) Applications
    Kamalrudin, Massila
    Ibrahim, Asma Asdayana
    Sidek, Safiah
    REQUIREMENTS ENGINEERING FOR INTERNET OF THINGS, 2018, 809 : 87 - 96