An official website of the European Union How do you know?      
European Commission logo
JRC Publications Repository Menu

Extending MUD profiles through an Automated IoT Security Testing Methodology

cover
Defining the intended behavior of IoT devices is considered as a key aspect to detect and mitigate potential security attacks. In this direction, the Manufacturer Usage Description (MUD) has been recently standardized to reduce the attack surface of a certain device through the definition of access control policies. However, the semantic model is only intended to provide network level restrictions for the communication of such device. In order to increase the expressivity of this approach, we propose the use of an automated IoT security testing methodology, so that testing results are used to generate augmented MUD profiles, in which additional security aspects are considered. Specifically, the methodology is based on the use of Model-Based Testing (MBT) techniques to automate the generation, design and implementation of security tests. Furthermore, we describe the application of the resulting approach to the Elliptic Curve Diffie- Hellman over COSE (EDHOC) protocol, which represent a standardization effort to build a lightweight authenticated key exchange protocol for IoT constrained scenarios.
2019-11-15
IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
JRC117730
2169-3536 (online),   
https://ieeexplore.ieee.org/document/8867876,    https://publications.jrc.ec.europa.eu/repository/handle/JRC117730,   
10.1109/ACCESS.2019.2947157 (online),   
Language Citation
NameCountryCityType
Datasets
IDTitlePublic URL
Dataset collections
IDAcronymTitlePublic URL
Scripts / source codes
DescriptionPublic URL
Additional supporting files
File nameDescriptionFile type 
Show metadata record  Copy citation url to clipboard  Download BibTeX
Items published in the JRC Publications Repository are protected by copyright, with all rights reserved, unless otherwise indicated. Additional information: https://ec.europa.eu/info/legal-notice_en#copyright-notice