IoT Security Seminar: Raising Awareness and Sharing Critical Knowledge

被引:0
作者
Goeman, Victor [1 ]
de Ruck, Dairo [1 ]
Bohe, Ilse [1 ]
Lapon, Jorn [1 ]
Naessens, Vincent [1 ]
机构
[1] Katholieke Univ Leuven, Imec DistriNet, Ghent, Belgium
来源
18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023 | 2023年
关键词
Education; IoT; Awareness; Cybersecurity;
D O I
10.1145/3600160.3604986
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The security of the Internet of Things (IoT) devices has become a major concern as the number of connected devices continues to increase. Despite this concern, there is a lack of training opportuni-ties to educate IoT developers on security measures. While there are ample ICT and Network Management courses for developers, there is a lack of security courses scoped for this audience. One of the reasons is that raising cybersecurity awareness and increasing the security expertise of developers presents a significant challenge due to the complexity of IoT security. This work presents a cybersecurity seminar that tackles these challenges. It is aimed at various actors in the IoT device develop-ment cycle (e.g. software designers, developers and managers) to raise IoT security awareness and share critical knowledge. It culti-vates the basics of both offensive and defensive security through a custom-built vulnerable IoT firmware image with vulnerabilities found in real-world IoT devices. This intentionally vulnerable im-age is accompanied by a detailed walkthrough explaining various exploitation and mitigation techniques. Our seminar has been held multiple times in both industry and academics and consistently received very positive feedback. It has been successful in educating participants about the importance of IoT security and providing them with additional knowledge and skills to take action in their own practices.
引用
收藏
页数:19
相关论文
共 26 条
[1]  
Alpine Linux, 2023, About us
[2]  
[Anonymous], 2023, JadX: Dex to Java Decompiler
[3]  
[Anonymous], 2023, Nmap: Discover your network
[4]  
[Anonymous], 2023, Kali Linux | Penetration Testing and Ethical Hacking Linux Distribution
[5]  
[Anonymous], 2019, OWASP IoT Goat
[6]  
[Anonymous], 2015, hashcat-advanced password recovery
[7]  
[Anonymous], 2023, OWASP Zed Attack Proxy
[8]  
[Anonymous], 2019, Cyberattacks On IOT Devices Surge 300% In 2019, 'Measured In Billions', Report Claims
[9]  
[Anonymous], 2017, Poky-Yocto Project
[10]  
[Anonymous], 2018, OWASP Internet of Things security team