Song Linxuan, García-Valls Marisol
Beijing University of Posts and Telecommunications, Beijing 100876, China.
Universitat Politècnica de València, 46022 Valencia, Spain.
Sensors (Basel). 2022 Jul 2;22(13):5004. doi: 10.3390/s22135004.
IoT (Internet of Things) systems are complex ones that may comprise large numbers of sensing and actuating devices; and servers that store data and further configure the operation of such devices. Usually, these systems involve real-time operation as they are closely bound to particular physical processes. This real-time operation is often threatened by the security solutions that are put in place to alleviate the ever growing attack surface in IoT. This paper focuses on critical IoT domains where less attention has been paid to the web security aspects. The main reason is that, up to quite recently, web technologies have been considered unreliable and had to be avoided by design in critical systems. In this work, we focus on the server side and on how attacks propagate from server to client as vulnerabilities and from client to unprotected servers; we describe the concerns and vulnerabilities introduced by the intensive usage of web interfaces in IoT from the server templating engines perspective. In this context, we propose an approach to perform self monitoring on the server side, propagating the self monitoring to the IoT system devices; the aim is to provide rapid detection of security vulnerabilities with a low overhead that is transparent to the server normal operation. This approach improves the control over the vulnerability detection. We show a set of experiments that validate the feasibility of our approach.
物联网(IoT)系统是复杂的系统,可能由大量传感和驱动设备以及存储数据并进一步配置此类设备操作的服务器组成。通常,这些系统涉及实时操作,因为它们与特定物理过程紧密相关。这种实时操作经常受到为缓解物联网中不断扩大的攻击面而实施的安全解决方案的威胁。本文关注的是物联网的关键领域,这些领域在网络安全方面受到的关注较少。主要原因是,直到最近,网络技术一直被认为不可靠,在关键系统中必须通过设计加以避免。在这项工作中,我们关注服务器端以及攻击如何从服务器传播到客户端(作为漏洞)以及从客户端传播到未受保护的服务器;我们从服务器模板引擎的角度描述了物联网中大量使用网络接口所带来的问题和漏洞。在此背景下,我们提出一种在服务器端进行自我监控的方法,并将自我监控传播到物联网系统设备;目的是在对服务器正常操作透明的情况下,以低开销快速检测安全漏洞。这种方法改进了对漏洞检测的控制。我们展示了一组实验,验证了我们方法的可行性。