Security Enhancement of IoT-based Edge Computing
Open AccessIoT devices have been more prevalent than ever before and IoT networks play an important role in industry as well as people's activities, which bring convenience to every aspect of our daily life. In order to fulfill the demand for communication efficiency of IoT and other industries, edge computing is also developing rapidly. Edge computing is a technique of separating the data and tasks of device system into different portions and offloading them to one or more edge servers for computation in order to optimize the efficiency of the system. Along with the rapid development of IoT and edge computing technologies, security in IoT fails to keep up with its pace due to device and technology heterogeneity and resource constraints and new vulnerabilities are derived from the combination of IoT and edge computing, making IoT-based edge computing systems susceptible to various attacks. In this dissertation, we target to effectively enhance the security performance of IoT devices and IoT-based edge computing networks. To be specific, we study this problem from the following three aspects. First, recent observations indicate that home use IoT devices are vulnerable in communications which carries abundant sensitive personal information. Thus, we first propose a novel graph-based mechanism to identify the vulnerabilities in communication of IoT devices for smart home systems. Our approach takes one or more packet capture files as inputs to construct a traffic graph by passing the captured messages, identify the correlated subgraphs by examining the attribute-value pairs associated with each message, and then quantify their vulnerabilities based on the sensitivity levels of different keywords. To test the effectiveness of our approach, we setup a smart home system that can control a smart bulb LB100 via either the smartphone APP for LB100 or the Google Home speaker. We collected and analyzed 58,714 messages and exploited 6 vulnerable correlated subgraphs, based on which we implemented 6 attack cases that can be easily reproduced by attackers with little knowledge of IoT. This study is novel as our approach takes only the collected traffic files as inputs without requiring the knowledge of the device firmware while being able to identify new vulnerabilities. Second, since health-related IoT devices have the access to users' sensitive health information or are even related to users' health, the new security attacks targeting the health-related IoT devices press an urgent need for the security analysis and defense strategies towards those attacks. With those consideration, we presented an in-depth security analysis on home-use electroencephalography (EEG) IoT devices. Our key contributions are twofold. First, we reverse-engineered the home-use EEG system framework via which we identified the design and implementation flaws. By exploiting these flaws, we developed two sets of novel easy-to-exploit PoC attacks, which consist of four remote attacks and one proximate attack. In a remote attack, an attacker can steal a user's brain wave data through a carefully crafted program while in the proximate attack, the attacker can steal a victim's brain wave data over-the-air without accessing the victim's device on any sense when he is close to the victim. As a result, all the 156 brain-computer interface (BCI) apps in the NeuroSky App store are vulnerable to the proximate attack. We also discovered that all the 31 free apps in the NeuroSky App store are vulnerable to at least one remote attack. Second, we proposed a novel deep learning model of a joint recurrent convolutional neural network (RCNN) to infer a user's activities based on the reduced-featured EEG data stolen from the home-use EEG IoT devices, and our evaluation over the real-world EEG data indicates that the inference accuracy of the proposed RCNN is as high as 73.2\%, which significantly outperforms 11 other well-known learning models. Third, alongside the convenience and new features generated from the combination of edge computing and IoT, their combination also introduces new security challenges which in turn cancels out their benefits to certain degree. With the analysis of security issues generated by the combination of edge computing and IoT, we target the defense techniques against IoT DDoS attacks and propose an edge-centric IoT defense scheme termed FlowGuard for the detection, identification, classification, and mitigation of IoT DDoS attacks. We present a new DDoS attack detection algorithm based on traffic variations and design two machine learning models for DDoS identification and classification. To demonstrate the effectiveness of the two machine learning models, we generate a large dataset by DDoS simulators BoNeSi and SlowHTTPTest, and combine it with the CICDDoS2019 dataset, to test the identification and classification accuracy as well as the model efficiency. Our results indicate that the identification accuracy of the proposed LSTM is as high as 98.9\%, which significantly outperforms the other four well-known learning models mentioned in the most related work. And the classification accuracy of the proposed CNN is up to 99.9\%. Besides, our models satisfactorily meet the delay requirements of IoT when deployed in edge servers with computational powers higher than a personal computer.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.