Hide metadata

dc.date.accessioned2020-06-30T07:45:23Z
dc.date.available2020-06-30T07:45:23Z
dc.date.created2020-06-19T13:59:30Z
dc.date.issued2020
dc.identifier.urihttp://hdl.handle.net/10852/77338
dc.description.abstractWe have previously proposed a security classification methodology for IoT systems and have applied it to the smart grid and smart home domain. This method departs from classical risk analysis and certification methods in that it caters for security at design time and for the system designers’ needs to know what protection mechanisms to use for the connectivity and exposure that their system under development requires. Though this method can be used for certification, after the system was built, much of the benefit comes in using it to decide what security features to choose to reach the desired security class. However, similarly to many risk analysis methods, this methodology is unable to assure the evaluation results by properly justifying the assessment. In this work we add two confidence parameters: belief and uncertainty to the assessment tree of arguments of a class. Thus, the final result will now be a tuple <C, B, U>, where C is the class to which the system under consideration belongs, along with a belief measure B in the evaluation aspects of C, and the uncertainty U in the evaluation details. Looking at the confidence parameters tells how well the security assessment is justified. To exemplify this enhanced security classification methodology, we systematically apply it to two control mechanisms for a Smart Home Energy Management Systems.
dc.languageEN
dc.publisherUniversitetet i Oslo
dc.relation.ispartofResearch report http://urn.nb.no/URN:NBN:no-35645
dc.relation.urihttp://urn.nb.no/URN:NBN:no-35645
dc.titleBuilding Confidence using Beliefs and Arguments in Security Class Evaluations for IoT (long version)
dc.typeResearch report
dc.creator.authorShrestha, Manish
dc.creator.authorJohansen, Christian
dc.creator.authorNoll, Josef
cristin.unitcode185,15,30,30
cristin.unitnameSeksjon for autonome systemer og sensorteknologier
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.fulltextpostprint
cristin.fulltextpostprint
cristin.fulltextoriginal
dc.identifier.cristin1816356
dc.identifier.pagecount22
dc.identifier.urnURN:NBN:no-80474
dc.type.documentForskningsrapport
dc.source.isbn978-82-7368-458-5
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/77338/5/TechnicalReport_Assurance_in_security_classes.pdf
dc.relation.projectNFR/248714
dc.relation.projectNFR/248113


Files in this item

Appears in the following Collection

Hide metadata