| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Analiza varnostnih ranljivosti interneta stvari : diplomsko delo visokošolskega študijskega programa Informacijska varnost
Authors:ID Kanduč, Luka (Author)
ID Prislan Mihelič, Kaja (Mentor) More about this mentor... New window
Files:.pdf VS_Kanduc_Luka_2020.pdf (722,22 KB)
MD5: 59DA668E099683C7A5FDE6601E37C2C1
PID: 20.500.12556/dkum/1e1e5289-81e4-43dd-945f-5eac814a4e08
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:Skladno s sodobnimi tehnološkimi trendi internet stvari (t.i. IoT) postaja vse bolj razširjen pojav, tako v poslovnem okolju kot vsakodnevnem življenju. Zaradi ogromnih količin podatkov in tveganj, ki nastajajo pri uporabi in delovanju IoT naprav, je postala njihova varnost pomembna raziskovalna tema. IoT naprave namreč zbirajo in obdelujejo osebne in občutljive uporabniške informacije in prav zaradi tega morajo biti odporne na grožnje in napade ter omogočiti zaupanje, varnost in zasebnost podatkov ter uporabnikov. Dosedanje raziskave kažejo, da je z delovanjem in uporabo IoT naprav povezanih ogromno ranljivosti, z zagotavljanjem varnosti pa so povezani številni izzivi, ki izhajajo iz kompleksne arhitekture in dinamičnega IoT okolja. Izziv predstavlja tudi eksponenten tehnološki napredek. Zaradi hitrosti razvoja IoT je namreč varnost pogosto zanemarjena. Namen diplomskega dela je bil opraviti pregled aktualnih varnostnih izzivov in ključnih ranljivosti, povezanih z delovanjem in uporabo IoT naprav. Cilj je bil ugotoviti, katere varnostne ranljivosti so najpogostejše in kakšne so njihove značilnosti. Skladno s tem je bila v empiričnem delu opravljena analiza ranljivosti povezanih z IoT napravami, vključenih v CVE podatkovno bazo, ki vključuje seznam javno znanih ranljivosti in izpostavljenosti na področju kibernetske varnosti. Rezultati kažejo, da lahko izkoriščanje ranljivosti IoT naprav v večini primerov vpliva na zaupnost, celovitost in dostopnost sistemov, pri čemer za izvedbo napada najpogosteje ni potrebna uporabniška interakcija, zadostuje pa že dostop preko interneta. Med najpogostejše ranljivosti sodijo neustrezne omejitve delovanja pri delu s pomnilnikom, možnosti vrivanja ukazov in neustrezno filtriranje vhodnih podatkov. Ugotovitve diplomskega dela prispevajo k razumevanju ključnih tveganj na področju IoT. Predstavljena priporočila za varen razvoj in izvedbo IoT naprav pa prispevajo k učinkovitejšemu načrtovanju in prenovi IoT naprav ter sistemov, saj se z upoštevanjem najpogostejših ranljivosti lahko odpravi velik del varnostnih tveganj.
Keywords:diplomske naloge, internet stvari, varnostne ranljivosti, stopnja tveganja, vektorji napadov, posledice
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:[L. Kanduč]
Year of publishing:2020
Year of performance:2020
Number of pages:V, 45 str.
PID:20.500.12556/DKUM-77230 New window
UDC:004.056:004.451.056(043.2)
COBISS.SI-ID:29624835 New window
NUK URN:URN:SI:UM:DK:CRY5VIJF
Publication date in DKUM:24.09.2020
Views:1296
Downloads:195
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Secondary language

Language:English
Title:Security vulnerabilities analysis of the internet of things
Abstract:The Internet of Things [IoT] is becoming an increasingly widespread phenomenon amongst modern technological trends. Due to the huge amounts of data generated by the use and operation of IoT devices, security has become an important research priority. IoT devices are collecting and processing personal and sensitive user data, which is why they must be resistant to threats and attacks and enable the trust, security, and privacy of data and users. Research to date has shown that the operation and use of IoT devices are associated with enormous vulnerabilities, and that security challenges are associated with a number of challenges arising from the complex architecture and dynamic IoT environment. Exponential technological advancement is also a challenge. Due to the high speed of IoT development, security is often being neglected. The purpose of the thesis was to review current security challenges and key vulnerabilities related to the operation and use of IoT devices. The aim was to determine the most common security vulnerabilities and describe their characteristics. Accordingly, in the empirical part, an analysis of vulnerabilities related to IoT devices included in the CVE database was performed. The database includes a list of publicly known cybersecurity vulnerabilities. The results showed that exploiting the vulnerabilities of IoT devices in most cases can affect the system confidentiality, integrity and availability, while most often no user interaction is required to carry out the attack, and internet access is mostly sufficient. The most common vulnerabilities include inadequate IoT device memory restrictions, command injection options, and improper input validation. The findings of the thesis contribute to the understanding of key security risks in the field of IoT. Presented recommendations for safe development and implementation of IoT devices contribute to more efficient design and rebuilding of IoT devices and systems, because considering the most common vulnerabilities can eliminate a great part of security risks.
Keywords:Internet of things, security vulnerabilities, risk level, attack vectors, consequences


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica