论文标题

物联网安全的最佳实践:这是什么意思?

Best Practices for IoT Security: What Does That Even Mean?

论文作者

Bellman, Christopher, van Oorschot, Paul C.

论文摘要

物联网(IoT)安全性的最佳实践最近引起了全球行业和政府的广泛关注,而学术研究强调了许多物联网产品制造商未能遵循公认的实践。我们探讨了未能遵循最佳实践,而是令人惊讶的是缺乏理解,而在文献中缺乏(一般)“最佳实践”意味着什么,而不是独立于有意义地识别特定的个人实践。从将期望的结果与安全实践相结合以实现这些结果的指南中可以明显看出混乱。最佳实践,良好实践和标准实践有何不同?还是指南,建议和要求?如果不可行,可以是最佳做法吗?我们考虑最佳实践的类别,以及它们如何应用于物联网设备的生命周期。为了在讨论中进行具体性,我们分析和分类了一组1014个物联网安全性最佳实践,建议和工业,政府和学术来源的准则。作为一个例子结果,我们发现这些做法或指南中约有70%与早期的物联网设备生命周期阶段有关,从而强调了制造商在解决有关的安全问题时的关键位置。我们希望我们的工作为社区提供基础,以便更好地了解最佳实践,确定并就特定实践达成共识,然后找到激励相关利益相关者关注他们的方法。

Best practices for Internet of Things (IoT) security have recently attracted considerable attention worldwide from industry and governments, while academic research has highlighted the failure of many IoT product manufacturers to follow accepted practices. We explore not the failure to follow best practices, but rather a surprising lack of understanding, and void in the literature, on what (generically) "best practice" means, independent of meaningfully identifying specific individual practices. Confusion is evident from guidelines that conflate desired outcomes with security practices to achieve those outcomes. How do best practices, good practices, and standard practices differ? Or guidelines, recommendations, and requirements? Can something be a best practice if it is not actionable? We consider categories of best practices, and how they apply over the lifecycle of IoT devices. For concreteness in our discussion, we analyze and categorize a set of 1014 IoT security best practices, recommendations, and guidelines from industrial, government, and academic sources. As one example result, we find that about 70\% of these practices or guidelines relate to early IoT device lifecycle stages, highlighting the critical position of manufacturers in addressing the security issues in question. We hope that our work provides a basis for the community to build on in order to better understand best practices, identify and reach consensus on specific practices, and then find ways to motivate relevant stakeholders to follow them.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源