68
Internet of Things (IoT)
• Insufficient security configurability
• Insecure software/firmware
• Poor physical security
Figure 4.6 shows the recent research done by Hp Fortify, which shows about IoT security
vulnerabilities.
4.3.2 Security Challenges
IoT should be built in such a way that it assures consumers that their communication is
done in a safe environment. To prevent an unauthorized user from accessing private data,
IoT faces many security challenges and they are shown in Figure 4.7.
IoT research should address the following issues:
• Event-driven agents should be available to enable an intelligent/self-aware
behavior of networked devices.
• Privacy-preserving technology for heterogeneous sets of devices.
• Models for decentralized authentication and trust.
• Energy-efficient encryption and data protection technologies.
• Security and trust for cloud computing.
• Data ownership.
• Legal and liability issues.
• Repository data management.
• Access and user rights, rules to share added value.
• Artificial immune systems solutions for IoT.
• Secure low-cost devices.
• Privacy policies management.
80%
70%
60%
50%
40%
30%
20%
10%
0%
Allow the
use of weak
passwords
Raise privacy
concerns over
the amount
of data that
they collect
Do not
encrypt data
transmissions
Cross-site
scripting or
other flaws in
web interfaces
Do not use
encryption when
downloading
software
FIGURE 4.6
Device-level IoT security vulnerabilities.
Internet of Things (IoT)
• Insufficient security configurability
• Insecure software/firmware
• Poor physical security
Figure 4.6 shows the recent research done by Hp Fortify, which shows about IoT security
vulnerabilities.
4.3.2 Security Challenges
IoT should be built in such a way that it assures consumers that their communication is
done in a safe environment. To prevent an unauthorized user from accessing private data,
IoT faces many security challenges and they are shown in Figure 4.7.
IoT research should address the following issues:
• Event-driven agents should be available to enable an intelligent/self-aware
behavior of networked devices.
• Privacy-preserving technology for heterogeneous sets of devices.
• Models for decentralized authentication and trust.
• Energy-efficient encryption and data protection technologies.
• Security and trust for cloud computing.
• Data ownership.
• Legal and liability issues.
• Repository data management.
• Access and user rights, rules to share added value.
• Artificial immune systems solutions for IoT.
• Secure low-cost devices.
• Privacy policies management.
80%
70%
60%
50%
40%
30%
20%
10%
0%
Allow the
use of weak
passwords
Raise privacy
concerns over
the amount
of data that
they collect
Do not
encrypt data
transmissions
Cross-site
scripting or
other flaws in
web interfaces
Do not use
encryption when
downloading
software
FIGURE 4.6
Device-level IoT security vulnerabilities.
