首页 | 本学科首页   官方微博 | 高级检索  
     

面向新攻击面的物联网终端固件安全威胁模型
引用本文:朱新兵,李清宝,张平,陈志锋,顾艳阳. 面向新攻击面的物联网终端固件安全威胁模型[J]. 计算机工程, 2021, 47(7): 126-134. DOI: 10.19678/j.issn.1000-3428.0059386
作者姓名:朱新兵  李清宝  张平  陈志锋  顾艳阳
作者单位:1. 中国人民解放军战略支援部队信息工程大学 网络空间安全学院, 郑州 450003;2. 数学工程与先进计算国家重点实验室, 郑州 450003;3. 中国人民解放军河南省军区 数据信息室, 郑州 450003
基金项目:国家自然科学基金(61802432)。
摘    要:物联网终端的显著特点是对外部世界进行感知与控制,但是传统安全威胁分析模型无法有效评估来自外部的攻击数据对物联网终端固件造成的危害.将新攻击面引入的攻击数据作为分析对象,通过对攻击数据在固件中的完整传播路径和交互过程进行建模,构建面向新攻击面的物联网终端固件安全威胁模型FSTM,从而分析物联网终端固件所面临的潜在威胁.分...

关 键 词:物联网  固件  新攻击面  攻击数据  安全威胁模型
收稿时间:2020-08-28
修稿时间:2020-09-29

Security Threat Model for IoT Terminal Firmware with a New Attack Surface
ZHU Xinbing,LI Qingbao,ZHANG Ping,CHEN Zhifeng,GU Yanyang. Security Threat Model for IoT Terminal Firmware with a New Attack Surface[J]. Computer Engineering, 2021, 47(7): 126-134. DOI: 10.19678/j.issn.1000-3428.0059386
Authors:ZHU Xinbing  LI Qingbao  ZHANG Ping  CHEN Zhifeng  GU Yanyang
Affiliation:1. Cyberspace Security College, PLA Strategic Support Force Information Engineering University, Zhengzhou 450003, China;2. State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou 450003, China;3. Data Information Office, PLA Henan Province Military Region, Zhengzhou 450003, China
Abstract:Internet of Things(IoT) terminals can perceive and control the external environment.However,the traditional security threat analysis models fail to accurately evaluate the harm of external attacks on IoT terminal firmware.This paper takes the attack data introduced by the new attack surface as the analysis object,and builds the model of the complete propagation path and interactions of the attack data in firmware.On this basis,a security threat model called FSTM for IoT terminal firmware with a new attack surface is constructed to support the analysis of potential threats faced by IoT terminal firmware.The analysis results show that FSTM can accurately describe the tight coupling between IoT and the physical world,as well as the strong correlation between IoT and the services.The proposed model provides theoretical guidance for the research of IoT terminal security and detection technology based on the new attack surface.
Keywords:Internet of Things(IoT)  firmware  new attack surface  attack data  security threat model  
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机工程》浏览原始摘要信息
点击此处可从《计算机工程》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号