Building Confidence using Beliefs and Arguments in Security Class Evaluations for IoT (long version)
dc.date.accessioned | 2020-06-30T07:45:23Z | |
dc.date.available | 2020-06-30T07:45:23Z | |
dc.date.created | 2020-06-19T13:59:30Z | |
dc.date.issued | 2020 | |
dc.identifier.uri | http://hdl.handle.net/10852/77338 | |
dc.description.abstract | We have previously proposed a security classification methodology for IoT systems and have applied it to the smart grid and smart home domain. This method departs from classical risk analysis and certification methods in that it caters for security at design time and for the system designers’ needs to know what protection mechanisms to use for the connectivity and exposure that their system under development requires. Though this method can be used for certification, after the system was built, much of the benefit comes in using it to decide what security features to choose to reach the desired security class. However, similarly to many risk analysis methods, this methodology is unable to assure the evaluation results by properly justifying the assessment. In this work we add two confidence parameters: belief and uncertainty to the assessment tree of arguments of a class. Thus, the final result will now be a tuple <C, B, U>, where C is the class to which the system under consideration belongs, along with a belief measure B in the evaluation aspects of C, and the uncertainty U in the evaluation details. Looking at the confidence parameters tells how well the security assessment is justified. To exemplify this enhanced security classification methodology, we systematically apply it to two control mechanisms for a Smart Home Energy Management Systems. | |
dc.language | EN | |
dc.publisher | Universitetet i Oslo | |
dc.relation.ispartof | Research report http://urn.nb.no/URN:NBN:no-35645 | |
dc.relation.uri | http://urn.nb.no/URN:NBN:no-35645 | |
dc.title | Building Confidence using Beliefs and Arguments in Security Class Evaluations for IoT (long version) | |
dc.type | Research report | |
dc.creator.author | Shrestha, Manish | |
dc.creator.author | Johansen, Christian | |
dc.creator.author | Noll, Josef | |
cristin.unitcode | 185,15,30,30 | |
cristin.unitname | Seksjon for autonome systemer og sensorteknologier | |
cristin.ispublished | true | |
cristin.fulltext | original | |
cristin.fulltext | postprint | |
cristin.fulltext | postprint | |
cristin.fulltext | original | |
dc.identifier.cristin | 1816356 | |
dc.identifier.pagecount | 22 | |
dc.identifier.urn | URN:NBN:no-80474 | |
dc.type.document | Forskningsrapport | |
dc.source.isbn | 978-82-7368-458-5 | |
dc.identifier.fulltext | Fulltext https://www.duo.uio.no/bitstream/handle/10852/77338/5/TechnicalReport_Assurance_in_security_classes.pdf | |
dc.relation.project | NFR/248714 | |
dc.relation.project | NFR/248113 |
Files in this item
Appears in the following Collection
-
Institutt for informatikk [4971]
-
CRIStin høstingsarkiv [31712]
-
Institutt for teknologisystemer [237]