Assessing the Feasibility of Adaptive Security Models for the Internet of Things

Waqas Aman

Research output: Chapter in Book/Report/Conference proceedingConference contribution

4 Citations (Scopus)

Abstract

Internet of Things (IoT) is a heterogeneous and dynamic space as it connects a variety of sensing, mobile and other physical objects. Traditional security controls and mechanisms tend to enforce pre-defined and manual risk mitigation approaches that manage security in a particular context. They seem to be insufficient in IoT scenarios that have a diverse and evolving technology outlook and threat spectrum. Adaptive security can be a suitable candidate for IoT security as it can observe and respond to threats dynamically. However, it is challenging to identify how practical are the existing adaptive security solutions in IoTdriven ecosystem. In this paper, we present an evaluation framework that assesses the feasibility of adaptive security models in IoT settings. The framework evaluates a given model from an adaptive risk management perspective and assesses the extent to which it is aware of its ecosystem. Moreover, it captures the essential features of a given model, such as adaptation aptitude and architectural aspects. Therefore, the framework determines the security as well as the architectural capabilities of a model. We have evaluated various models and have identified major trends and gaps in their modeling approaches.

Original languageUndefined/Unknown
Title of host publicationHuman Aspects of Information Security, Privacy, and Trust - 4th International Conference, HAS 2016, Held as Part of HCI International 2016, Toronto, ON, Canada, July 17-22, 2016, Proceedings
EditorsTheo Tryfonas
PublisherSpringer
Pages201-211
Number of pages11
Volume9750
ISBN (Print)9783319393803
DOIs
Publication statusPublished - 2016
Event4th International Conference on Human Aspects of Information Security, Privacy, and Trust, HAS 2016 and Held as Part of 18th International Conference on Human-Computer Interaction, HCI International 2016 - Toronto, Canada
Duration: Jul 17 2016Jul 22 2016

Publication series

NameLecture Notes in Computer Science
PublisherSpringer

Conference

Conference4th International Conference on Human Aspects of Information Security, Privacy, and Trust, HAS 2016 and Held as Part of 18th International Conference on Human-Computer Interaction, HCI International 2016
Country/TerritoryCanada
CityToronto
Period7/17/167/22/16

Keywords

  • Adaptive security
  • Feasibility
  • Internet of things
  • Risk management

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Cite this