Source-linked AI summary
Security Risk Assessment in Internet of Things Systems
Jason R. C. Nurse, Sadie Creese, David De Roure
TL;DR
Existing risk assessment methods may miss risks in IoT because they were developed before highly connected digital, cyber-physical, and social systems became pervasive. The article analyzes this mismatch and argues for automated, continuous, and predictive approaches that account for IoT dynamics and trust variability. It also identifies limitations in current quantitative and dynamic assessment practice, including analytical complexity, insufficient data, and periodic assessment.
Problem
Existing risk assessment methods may overlook IoT risks arising from highly connected digital, cyber-physical, and social systems and their dynamic relationships.
Method
The article analyzes why current approaches are unsuitable for IoT and develops the case for automated, continuous, predictive assessment incorporating IoT dynamics and trust variability.
Results
The article concludes that IoT risk assessment must account for changing scale, relationships, trust, risk propagation, and assets that can serve as attack platforms.
Takeaways & Limitations
New IoT risk methods should preserve rigorous risk assessment while addressing highly dynamic, interconnected systems and the processes that bind their actors.
Takeaways & Limitations
Current quantitative techniques face analytical complexity and insufficient data, while dynamic assessment remains limited and periodic assessment remains prevalent.
Abstract
from arXiv · showhide
Information security risk assessment methods have served us well over the past two decades. They have provided a tool for organizations and governments to use in protecting themselves against pertinent risks. As the complexity, pervasiveness, and automation of technology systems increases and cyberspace matures, particularly with the Internet of Things (IoT), there is a strong argument that we will need new approaches to assess risk and build trust. The challenge with simply extending existing assessment methodologies to IoT systems is that we could be blind to new risks arising in such ecosystems. These risks could be related to the high degrees of connectivity present or the coupling of digital, cyber-physical, and social systems. This article makes the case for new methodologies to assess risk in this context that consider the dynamics and uniqueness of the IoT while maintaining the rigor of best practice in risk assessment.
1. Introduction
IoT increases the security and trust challenge because digital, cyber-physical, and social systems are becoming pervasive, automated, and tightly coupled. The article argues that existing risk assessment approaches may miss risks arising from these IoT characteristics, requiring new approaches developed across relevant stakeholder communities.
- IoT couples digital, cyber-physical, and social systems across relationships that vary in density, time, and automation.
- Existing risk assessment methodologies predate IoT and may not accommodate the complexity and pervasiveness of automated IoT systems.
- Applying existing methods to IoT may leave organizations blind to emerging cyber-attacks and population-scale social processes.
- The article analyzes why current approaches are unsuitable for IoT and highlights new methods as a basis for trust in IoT-based systems.
- The proposed methodological development should involve industry, government, and academia to address threats facing IoT.
2. The current cybersecurity risk assessment paradigm
Cybersecurity risk assessment identifies and prioritizes risks, but methods differ in what they center and how they measure risk. Quantitative and dynamic approaches remain difficult to apply in complex, interconnected systems because of analytical complexity and limited estimation data.
- Core concepts of risk assessment: Risk assessment identifies, estimates, and prioritizes risks to organizational assets and operations before selecting treatment options.Treatment may involve acceptance, mitigation, transfer, or avoidance.
- Approaches to risk assessment: Common methodologies include NIST SP800-30, ISO/IEC 27001, OCTAVE, CRAMM, and EBIOS, with implementation varying by context and organization.
- Approaches to risk assessment: Asset-oriented approaches begin with critical assets, whereas threat-oriented approaches emphasize threats and their feasibility.Asset orientation centers assessments on important assets; threat orientation is better suited to current threat landscapes.
- Approaches to risk assessment: Qualitative likelihood and impact ratings are widely used because they simplify risk measurement, risk appetite setting, and communication.
- Approaches to risk assessment: Probabilistic and quantitative techniques can be complex, error-prone, difficult to communicate, and constrained by insufficient data for estimating likelihood and impact.These limitations have restricted their use in complex, highly interconnected systems and contributed to the prevalence of periodic assessments.
3. The relevant dynamics of IoT
IoT systems vary in scale, connection temporality, and actor heterogeneity, creating dynamic relationships across devices, people, and systems. Risk assessment must therefore account not only for components but also for the connections and processes that bind them.
- Scale: IoT can expand or shrink across a wide range of systems and things, with digital functionality embedded throughout natural and constructed environments.
- Dynamism and temporality: Connections between IoT devices may be temporary or persistent, and their temporality affects risk and the resources needed for management and control.Persistent connections from unauthorized devices are identified as one example of the resulting risk.
- Actor heterogeneity: IoT ecosystems may contain heterogeneous actors, including devices, people, and systems, often accessible across organizations and uniquely addressable online.
- Actor heterogeneity: Spontaneous or temporal relationships can make misbehaving actors difficult to track and risks difficult to locate or trace across distributed devices.
- The binding “glue”: Security and trust research often emphasizes device components and interfaces while giving less attention to the processes and connections that bind variable actors.The article identifies this binding “glue” as especially important in cyber-physical and cyber-social systems.
4. Where current risk assessment methods fail within IoT
Current risk assessment methods struggle with IoT because systems change rapidly, boundaries are difficult to understand, and connected devices can become attack platforms.
- Shortcomings of periodic assessment: Periodic assessments can miss emerging IoT systems because the scale and configuration of these environments vary between assessment cycles.Effective assessment would need to anticipate systems that may emerge before the next periodic review.
- Changing systems boundaries yet limited system knowledge: IoT systems may change shape faster than periodic assessments can account for, while assessors may lack comprehensive knowledge of their environments.The passage identifies changing system boundaries and limited system knowledge as linked challenges.
- The challenge of understanding the glue: IoT connections and actor behaviours can create exploitable effects, but existing risk assessment practices do not account for this system “glue.”The glue includes protocols, communications, data processing, and responses that become inputs to other actors.
- Failure to consider assets as an attack platform: IoT devices and other assets may be taken over and used as distributed cyber-weapons, whereas current assessments mainly treat assets as things of organisational value.The 2016 Dyn cyberattack is cited as an example of compromised IoT devices being used in an attack.
5. The need for new approaches to assess IoT system risk
The paper argues that IoT requires risk assessment approaches that account for interconnected, changing systems rather than treating them as isolated systems assessed periodically.
- Why current approaches are insufficient: Current methodologies can miss failures and knock-on effects arising from pervasive coupling among digital, cyber-physical, and social systems.The paper states that existing approaches were established before this pervasive coupling and increasing automation.
- Requirements for new approaches: New approaches should support automated and continuous assessment, with simulation and modelling to improve prediction of changing IoT risks.The proposed direction combines automated techniques with research on risk analysis in inter-dependent systems.
- Requirements for new approaches: IoT risk assessment may need near-real-time support that predicts emerging risks and accounts for propagation of physical, social, and economic harms.The paper links this requirement to changing environments and the ability of repurposed devices or actors to facilitate unexpected harms.
Biographies
The supplied passage contains publication-statistics text rather than biographical information.
- The passage reads “View publication stats” and provides no biographical details.