- Practical Internet of Things Security
- Brian Russell Drew Van Duren
- 224字
- 2021-06-10 18:42:31
Step 3 – decompose the IoT system
At this stage, the focus is on understanding the life cycle of data as it flows through the system. This understanding allows us to identify vulnerable or weak points that must be addressed within the security architecture. To start, you must identify and document the entry points for data within the system. These points are typically sensors, gateways, or control and management computing resources.
Next, it is important to trace the flow of data from the entry points and document the various components that interact with that data throughout the system. Identify high-profile targets for attackers (these can be intermediate or top-level nodes of an attack tree)—these may be points within the system that aggregate or store data, or they may be high-value sensors that require significant protection to maintain the overall integrity of the system. At the end of this activity, a detailed understanding of the IoT system's attack surface (in terms of data sensitivity and system movements) emerges:
Once data flows have been thoroughly examined, you can begin to catalogue the various physical entry points into the system and the intermediate and internal gateways through which data flows. Also, identify trust boundaries. The entry points and trust boundaries have an enormous security bearing as you identify overall threats associated with the system:

- API安全實戰
- Metasploit Penetration Testing Cookbook(Third Edition)
- INSTANT Metasploit Starter
- 計算機使用安全與防護
- Kerberos域網絡安全從入門到精通
- 網絡安全應急響應實戰
- Mastering Reverse Engineering
- 網絡用戶行為的安全可信分析與控制
- VMware vCloud Security
- 構建新型網絡形態下的網絡空間安全體系
- 網絡服務安全與監控
- CTF快速上手:PicoCTF真題解析(Web篇)
- Hands-On Artificial Intelligence for Cybersecurity
- 企業數據安全防護指南
- Mastering Metasploit