IoT security through cyclic, precisely meshed threat analysis and attack detection

Intelligent technical systems are highly, dynamically, partly networked via the Internet and thus form so-called IoT systems (Internet of Things). In mechanical & plant engineering, plants, machines and controllers (PLCs) are networked with each other and with cloud services through Industry 4.0 use cases. In the smart home, home appliances, such as washing machines and kitchen appliances, are controlled via consumer IoT devices and smartphone apps. ATMs consist inherently of networked subcomponents such as PIN pads, card readers and bill transport systems and communicate with banking IT and cash card institutions. The increasing networking of the systems with the outside world greatly increases the attack surface in terms of IT security. International security standards therefore require the integration of appropriate countermeasures in the systems, e.g., for the encryption of data or the detection of attacks by means of attack detection systems (ADS). However, it is sometimes extremely costly or even impossible to monitor the entire system using ADS. For this reason, the standards also require a so-called threat analysis to be carried out. This identifies vulnerable subsystems in order to deploy appropriate countermeasures where the risk is appropriately high and the effectiveness of the measure is promising, leaving only an acceptable residual risk. The overall goal of this project is to facilitate the development and maintenance of secure IoT systems according to the security-by-design paradigm - over the entire system lifetime. A systematic, tool-supported and iterative dovetailing of threat analysis at development time with attack detection at system runtime should make this possible. To this end, the threat analysis and, in particular, the precise derivation of suitable security measures and ADS monitoring targets will be supported. For this purpose, the project will support the precise selection of components to be monitored and the associated development of the ADS. In addition, the findings from the application of the ADS, i.e. detected attacks, will be fed back into the threat analysis in order to re-evaluate the threat risk if necessary and to revise countermeasures - i.e. to plan security updates. Thus, by repeatedly running through the Secure Development Lifecycle, the high security level of the systems should be continuously checked and maintained.

Fraunhofer-Institut für Entwurfstechnik Mechatronik IEM

Markus Fockel

Markus Fockel

Gruppenleiter

Details

IoT-ScuBA

€1,170,000.00

Ministerium für Wirtschaft, Industrie, Klimaschutz und Energie des Landes Nordrhein-Westfalen

it's OWL

Problem

International security standards require the integration of appropriate countermeasures into the systems, e.g. for the encryption of data or the detection of attacks by means of attack detection systems (ADS). However, depending on the system, it is extremely costly or even impossible to monitor the entire system using ADS. For this reason, the standards also require a so-called threat analysis to be carried out. This identifies subsystems at risk in order to implement appropriate countermeasures where the risk is correspondingly high and the effectiveness of the measure is promising, so that only an acceptable residual risk remains.

However, the two areas of attack detection and threat analysis are only considered separately from each other, leaving synergy effects unused.

Objective and Approach

The overall goal of this project is to facilitate the development and maintenance of secure IoT systems according to the security-by-design paradigm - over the entire system lifetime. A systematic, tool-supported and iterative dovetailing of threat analysis at development time with attack detection at system runtime shall enable this. For this purpose, the threat analysis and in particular the precise derivation of suitable security measures as well as ADS monitoring targets will be supported. For this purpose, the project will support the precise selection of components to be monitored and the associated development of the ADS. In addition, the findings from the application of the ADS, i.e. detected attacks, will be fed back into the threat analysis in order to re-evaluate the threat risk if necessary and to revise countermeasures - i.e. to plan security updates. Thus, by repeatedly running through the Secure Development Lifecycle, the high security level of the systems should be continuously checked and maintained. 

Results and Values

The project aims to facilitate the development and maintenance of secure IoT systems according to the security-by-design paradigm and to enable a systematic, tool-supported and iterative interlocking of threat analysis at development time with attack detection at system runtime. The aim is to achieve the following concrete results:

  1. 

Facilitation of threat analysis and derivation of countermeasures: A central goal of the project is to develop a tool that enables developers, even without in-depth security expertise, to model the architecture of their system using data flow diagrams (DFD). This tool is intended to support precise threat analysis and automatically suggest suitable countermeasures. These measures are so precise that they meet the requirements of relevant standards and provide developers with clear implementation instructions. In addition, the tool is designed to support the selection and configuration of commercial off-the-shelf (COTS) components with security features by identifying their security features and checking whether they can mitigate the identified threats.

  1. 

Application-based, distributed attack detection (ADS): Another significant goal is to develop a framework for efficient, application-based attack detection. This framework should enable the targeted monitoring of software components and support a variety of communication protocols as well as integration into security information and event management systems. By using threat analysis results, monitoring points are identified that monitor particularly security-critical behavioral artifacts. Machine learning (ML) methods are to be used to detect anomalies, which learn the normal behavior of the monitored system and identify deviations without the need for manual specification of attacks. Automated selection and configuration of the detection methods using Automated Machine Learning (AutoML) supports this process.

  1. 

Interlocking threat analysis and attack detection: A systematic and iterative process is being developed to ensure effective dovetailing of threat analysis and attack detection. This process should facilitate the derivation of monitoring targets from threat analysis results and enable the feedback of detection data collected during runtime into the threat analysis. This enables continuous updating and reassessment of threat risks. The data collected during system runtime is processed so that it can be integrated into the existing threat model and used for threat risk assessment. This contributes to the continuous improvement and maintenance of the high security level of the systems.

These measures continuously improve the security of IoT systems throughout their entire life cycle. This also contributes to sustainability by avoiding premature system scrapping and waste of resources. The project thus helps to meet the high security requirements of future IoT systems and ensure their long-term reliability and security.

Involved Partners

Paderborn, Germany

1859

Diebold Nixdorf

Gütersloh, Germany

1899

Miele & Cie. KG