217
IoT Challenges
11.6.1.1 Blacklisting versus Whitelisting
Whitelisting took the place of blacklisting as it is easier to allow only what is necessary and
deny the rest of the requests. It was better than the conventional antivirus techniques that
would scan for malware in each and every input file. Whitelisting, on the contrary, only
allows the authentic applications blocking every other one (http://searchsecurity.techtarget.com/answer/Application-whitelisting-vs-blacklisting-Which-is-the-way-forward).
Figure 11.4 is an illustration of blacklisting and whitelisting.
The blacklisting method is becoming more inefficient because of the increasing saturation of malware. In order to update a blacklist, the services based on a cloud which accumulates the data from several nodes because of which it becomes a less burdensome task
to keep a whitelist.
However, there are certain functional constraints in maintaining an application whitelist
when the conventional blacklist methodologies are proved to be less efficient. While
whitelist holds the capability of blocking the unauthorized files and data from entering
the system it is installed in, it can restrain the initial acceptance of the recent and more
advanced methodologies and technologies.
Blacklisting
Whitelisting
FIGURE 11.4
Representation of blacklisting and whitelisting.
TABLE 11.1
Security Features and Their Respective Applications in the Embedded Appliances
Security
Application in Embedded Appliances
Safe booting
Obtained from the producer with the help of a cryptographically signed code as well
as with the hardware support to validate the code. This ensures that there has not
been any changes made in the firmware.
Secure code revision
A technique of revisions of safe code that ensures that the code in the appliance can
be revised for fixing the errors, safety patches, etc.
Information security
Avoids access without an official permission or approval to the appliances.
Prevents the transmission of encrypted data and retention of the same.
Authentication
All the transmission of data with the appliance must be validated through passwords
of good strength.
Safe transmission and
reception
The transmission to and reception from the appliance require a secure encrypted
protocol in order to prevent the usage of unsafe encryption algorithms; care
should be taken.
Safeguarding against
cyber intrusions
This involves introduction of the embedded firewalls for preventing intrusions.
A firewall has the ability to include only the known, trusted users, thereby
preventing the hackers from even initiating the intrusions.
Source: Alan Grau. (2014). What is Really Needed to Secure the Internet of Things?. Icon Labs Whitepaper. https://
www.automation.com/pdf_articles/Internet_of_Secure_Things.pdf.
Précédent

- 242/358

Suivant