Skip to main content
Erschienen in: Telecommunication Systems 1/2017

13.05.2016

Security assessment framework for IoT service

verfasst von: Keon Chul Park, Dong-Hee Shin

Erschienen in: Telecommunication Systems | Ausgabe 1/2017

Einloggen

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

What are the critical requirements to be considered for the security measures in Internet of Things (IoT) services? Further, how should those security resources be allocated? To provide valuable insight into these questions, this paper introduces a security assessment framework for the IoT service environment from an architectural perspective. Our proposed framework integrates fuzzy DEMATEL and fuzzy ANP to reflect dependence and feedback interrelations among security criteria and, ultimately, to weigh and prioritize them. The results, gleaned from the judgments of 38 security experts, revealed that security design should put more importance on the service layer, especially to ensure availability and trust. We believe that these results will contribute to the provision of more secure and reliable IoT services.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Abomhara, M., & Koien, G. M. (2014, May). Security and privacy in the Internet of Things: Current status and open issues. Paper presented at the 2nd international conference on privacy and security in mobile systems, Aalborg. doi:10.1109/PRISMS.2014.6970594 Abomhara, M., & Koien, G. M. (2014, May). Security and privacy in the Internet of Things: Current status and open issues. Paper presented at the 2nd international conference on privacy and security in mobile systems, Aalborg. doi:10.​1109/​PRISMS.​2014.​6970594
4.
Zurück zum Zitat Babar, S., Mahalle, P., Stango, A., Prasad, N., & Prasad, R. (2010). Proposed security model and threat taxonomy for the Internet of things. In N. Meghanathan, et al. (Eds.), Recent trends in network security and applications (pp. 420–429). Berlin: Springer.CrossRef Babar, S., Mahalle, P., Stango, A., Prasad, N., & Prasad, R. (2010). Proposed security model and threat taxonomy for the Internet of things. In N. Meghanathan, et al. (Eds.), Recent trends in network security and applications (pp. 420–429). Berlin: Springer.CrossRef
7.
Zurück zum Zitat Büyüközkan, G., & Çifçi, G. (2012). A novel hybrid MCDM approach based on fuzzy DEMATEL, fuzzy ANP and fuzzy TOPSIS to evaluate green suppliers. Expert Systems with Applications, 39(3), 3000–3011. doi:10.1016/j.eswa.2011.08.162.CrossRef Büyüközkan, G., & Çifçi, G. (2012). A novel hybrid MCDM approach based on fuzzy DEMATEL, fuzzy ANP and fuzzy TOPSIS to evaluate green suppliers. Expert Systems with Applications, 39(3), 3000–3011. doi:10.​1016/​j.​eswa.​2011.​08.​162.CrossRef
9.
Zurück zum Zitat Chen, J.-K., & Chen, I.-S. (2010). Using a novel conjunctive MCDM approach based on DEMATEL, fuzzy ANP, and TOPSIS as an innovation support system for Taiwanese higher education. Expert Systems with Applications, 37(3), 1981–1990. doi:10.1016/j.eswa.2009.06.079.CrossRef Chen, J.-K., & Chen, I.-S. (2010). Using a novel conjunctive MCDM approach based on DEMATEL, fuzzy ANP, and TOPSIS as an innovation support system for Taiwanese higher education. Expert Systems with Applications, 37(3), 1981–1990. doi:10.​1016/​j.​eswa.​2009.​06.​079.CrossRef
10.
Zurück zum Zitat Chen-Yi, H., Ke-Ting, C., & Gwo-Hshiung, T. (2007). FMCDM with fuzzy DEMATEL approach for customers’ choice behavior model. International Journal of Fuzzy Systems, 9(4), 236–246. Chen-Yi, H., Ke-Ting, C., & Gwo-Hshiung, T. (2007). FMCDM with fuzzy DEMATEL approach for customers’ choice behavior model. International Journal of Fuzzy Systems, 9(4), 236–246.
11.
12.
Zurück zum Zitat Cirani, S., Ferrari, G., & Veltri, L. (2013). Enforcing security mechanisms in the IP-based internet of things: An algorithmic overview. Algorithms, 6(2), 197–226. doi:10.3390/a6020197.CrossRef Cirani, S., Ferrari, G., & Veltri, L. (2013). Enforcing security mechanisms in the IP-based internet of things: An algorithmic overview. Algorithms, 6(2), 197–226. doi:10.​3390/​a6020197.CrossRef
13.
Zurück zum Zitat Covington, M. J., & Carskadden, R. (2013, June). Threat implications of the internet of things. In 2013 5th IEEE International conference on cyber conflict (pp. 1–12). Covington, M. J., & Carskadden, R. (2013, June). Threat implications of the internet of things. In 2013 5th IEEE International conference on cyber conflict (pp. 1–12).
18.
Zurück zum Zitat Gabus, A., & Fontela, E. (1972). World problems, an invitation to further thought within the framework of DEMATEL. Geneva: Battelle Geneva Research Center. Gabus, A., & Fontela, E. (1972). World problems, an invitation to further thought within the framework of DEMATEL. Geneva: Battelle Geneva Research Center.
19.
Zurück zum Zitat Gazis, V., Sasloglou, K., Frangiadakis, N., & Kikiras, P. (2012, October). Wireless sensor networking, automation technologies and machine to machine developments on the path to the Internet of Things. Paper presented at 16th Panhellenic conference on informatics (PCI), Piraeus. doi:10.1109/PCi.2012.64 Gazis, V., Sasloglou, K., Frangiadakis, N., & Kikiras, P. (2012, October). Wireless sensor networking, automation technologies and machine to machine developments on the path to the Internet of Things. Paper presented at 16th Panhellenic conference on informatics (PCI), Piraeus. doi:10.​1109/​PCi.​2012.​64
21.
Zurück zum Zitat Guillemin, P., & Friess, P. (2009, September). Internet of things strategic research roadmap. The Cluster of European Research Projects. Technical Report. Guillemin, P., & Friess, P. (2009, September). Internet of things strategic research roadmap. The Cluster of European Research Projects. Technical Report.
23.
Zurück zum Zitat Karsak, E. E., & Tolga, E. (2001). Fuzzy multi-criteria decision-making procedure for evaluating advanced manufacturing system investments. International Journal of Production Economics, 69(1), 49–64. doi:10.1016/S0925-5273(00)00081-5.CrossRef Karsak, E. E., & Tolga, E. (2001). Fuzzy multi-criteria decision-making procedure for evaluating advanced manufacturing system investments. International Journal of Production Economics, 69(1), 49–64. doi:10.​1016/​S0925-5273(00)00081-5.CrossRef
27.
Zurück zum Zitat Mardani, A., Jusoh, A., & Zavadskas, E. K. (2015). Fuzzy multiple criteria decision-making techniques and applications–Two decades review from 1994 to 2014. Expert Systems with Applications, 42(8), 4126–4148. doi:10.1016/j.eswa.2015.01.003.CrossRef Mardani, A., Jusoh, A., & Zavadskas, E. K. (2015). Fuzzy multiple criteria decision-making techniques and applications–Two decades review from 1994 to 2014. Expert Systems with Applications, 42(8), 4126–4148. doi:10.​1016/​j.​eswa.​2015.​01.​003.CrossRef
34.
Zurück zum Zitat Önüt, S., Kara, S. S., & Işik, E. (2009). Long term supplier selection using a combined fuzzy MCDM approach: A case study for a telecommunication company. Expert Systems with Applications, 36(2), 3887–3895. doi:10.1016/j.eswa.2008.02.045.CrossRef Önüt, S., Kara, S. S., & Işik, E. (2009). Long term supplier selection using a combined fuzzy MCDM approach: A case study for a telecommunication company. Expert Systems with Applications, 36(2), 3887–3895. doi:10.​1016/​j.​eswa.​2008.​02.​045.CrossRef
35.
36.
Zurück zum Zitat Ramik, J. (2007). A decision system using ANP and fuzzy inputs. International Journal of Innovative Computing, Information and Control, 3(4), 825–837. Ramik, J. (2007). A decision system using ANP and fuzzy inputs. International Journal of Innovative Computing, Information and Control, 3(4), 825–837.
38.
Zurück zum Zitat Roman, R., Zhou, J., & Lopez, J. (2013). On the features and challenges of security and privacy in distributed internet of things. Computer Networks, 57(10), 2266–2279.CrossRef Roman, R., Zhou, J., & Lopez, J. (2013). On the features and challenges of security and privacy in distributed internet of things. Computer Networks, 57(10), 2266–2279.CrossRef
39.
Zurück zum Zitat Saaty, T. L. (1996). The analytic network process: Decision making with dependence and feedback; the organization and prioritization of complexity. Pittsburgh, PA: RWS Publications. Saaty, T. L. (1996). The analytic network process: Decision making with dependence and feedback; the organization and prioritization of complexity. Pittsburgh, PA: RWS Publications.
40.
Zurück zum Zitat Saaty, T. L. (2006). The analytic network process. In T. L. Saaty & L. G. Vargas (Eds.), Decision making with the analytic network process (pp. 1–26). Berlin: Springer.CrossRef Saaty, T. L. (2006). The analytic network process. In T. L. Saaty & L. G. Vargas (Eds.), Decision making with the analytic network process (pp. 1–26). Berlin: Springer.CrossRef
41.
Zurück zum Zitat Shin, D. (2010). The effects of trust, security and privacy in social networking: A security-based approach to understand the pattern of adoption. Interacting with Computers, 22(5), 428–438.CrossRef Shin, D. (2010). The effects of trust, security and privacy in social networking: A security-based approach to understand the pattern of adoption. Interacting with Computers, 22(5), 428–438.CrossRef
42.
Zurück zum Zitat Shin, D. (2014). A socio-technical framework for Internet-of-Things design: A human-centered design for the Internet of Things. Telematics and Informatics, 31(4), 519–531.CrossRef Shin, D. (2014). A socio-technical framework for Internet-of-Things design: A human-centered design for the Internet of Things. Telematics and Informatics, 31(4), 519–531.CrossRef
43.
Zurück zum Zitat Shin, D. (2015). Effect of the customer experience on satisfaction with smartphones: Assessing smart satisfaction index with partial least squares. Telecommunications Policy, 39(8), 627–641.CrossRef Shin, D. (2015). Effect of the customer experience on satisfaction with smartphones: Assessing smart satisfaction index with partial least squares. Telecommunications Policy, 39(8), 627–641.CrossRef
44.
Zurück zum Zitat Sun, C.-C. (2010). A performance evaluation model by integrating fuzzy AHP and fuzzy TOPSIS methods. Expert Systems with Applications, 37(12), 7745–7754.CrossRef Sun, C.-C. (2010). A performance evaluation model by integrating fuzzy AHP and fuzzy TOPSIS methods. Expert Systems with Applications, 37(12), 7745–7754.CrossRef
45.
Zurück zum Zitat Syamsuddin, I., & Hwang, J. (2010, October). A new fuzzy MCDM framework to evaluate e-government security strategy. Paper presented at 2010 4th international conference on application of information and communication technologies, Uzbekistan. Syamsuddin, I., & Hwang, J. (2010, October). A new fuzzy MCDM framework to evaluate e-government security strategy. Paper presented at 2010 4th international conference on application of information and communication technologies, Uzbekistan.
46.
Zurück zum Zitat Tadić, S., Zečević, S., & Krstić, M. (2014). A novel hybrid MCDM model based on fuzzy DEMATEL, fuzzy ANP and fuzzy VIKOR for city logistics concept selection. Expert Systems with Applications, 41(18), 8112–8128. doi:10.1016/j.eswa.2014.07.021.CrossRef Tadić, S., Zečević, S., & Krstić, M. (2014). A novel hybrid MCDM model based on fuzzy DEMATEL, fuzzy ANP and fuzzy VIKOR for city logistics concept selection. Expert Systems with Applications, 41(18), 8112–8128. doi:10.​1016/​j.​eswa.​2014.​07.​021.CrossRef
47.
Zurück zum Zitat Tavana, M., Zandi, F., & Katehakis, M. N. (2013). A hybrid fuzzy group ANP-TOPSIS framework for assessment of e-government readiness from a CiRM perspective. Information & Management, 50(7), 383–397.CrossRef Tavana, M., Zandi, F., & Katehakis, M. N. (2013). A hybrid fuzzy group ANP-TOPSIS framework for assessment of e-government readiness from a CiRM perspective. Information & Management, 50(7), 383–397.CrossRef
48.
49.
Zurück zum Zitat Turskis, Z., Zavadskas, E. K., & Peldschus, F. (2009). Multi-criteria optimization system for decision making in construction design and management. Engineering Economics, 61(1), 7–17. Turskis, Z., Zavadskas, E. K., & Peldschus, F. (2009). Multi-criteria optimization system for decision making in construction design and management. Engineering Economics, 61(1), 7–17.
50.
Zurück zum Zitat Tuzkaya, G., Ozgen, A., Ozgen, D., & Tuzkaya, U. (2009). Environmental performance evaluation of suppliers: A hybrid fuzzy multi-criteria decision approach. International Journal of Environmental Science & Technology, 6(3), 477–490. doi:10.1007/BF03326087.CrossRef Tuzkaya, G., Ozgen, A., Ozgen, D., & Tuzkaya, U. (2009). Environmental performance evaluation of suppliers: A hybrid fuzzy multi-criteria decision approach. International Journal of Environmental Science & Technology, 6(3), 477–490. doi:10.​1007/​BF03326087.CrossRef
51.
Zurück zum Zitat Tuzkaya, U. R., & Önüt, S. (2008). A fuzzy analytic network process based approach to transportation-mode selection between Turkey and Germany: A case study. Information Sciences, 178(15), 3133–3146. doi:10.1016/j.ins.2008.03.015.CrossRef Tuzkaya, U. R., & Önüt, S. (2008). A fuzzy analytic network process based approach to transportation-mode selection between Turkey and Germany: A case study. Information Sciences, 178(15), 3133–3146. doi:10.​1016/​j.​ins.​2008.​03.​015.CrossRef
52.
Zurück zum Zitat Uygun, Ö., Kaçamak, H., & Kahraman, Ü. A. (2014). An integrated DEMATEL and Fuzzy ANP techniques for evaluation and selection of outsourcing provider for a telecommunication company. Computers & Industrial Engineering,. doi:10.1016/j.cie.2014.09.014. Uygun, Ö., Kaçamak, H., & Kahraman, Ü. A. (2014). An integrated DEMATEL and Fuzzy ANP techniques for evaluation and selection of outsourcing provider for a telecommunication company. Computers & Industrial Engineering,. doi:10.​1016/​j.​cie.​2014.​09.​014.
54.
Zurück zum Zitat Vuković, D. (2014). Security issues in Internet of Things (IOT) related to passive RFID tags. Facta Universitatis, Series: Automatic Control and Robotics, 13(2), 97–105. Vuković, D. (2014). Security issues in Internet of Things (IOT) related to passive RFID tags. Facta Universitatis, Series: Automatic Control and Robotics, 13(2), 97–105.
57.
61.
Zurück zum Zitat Yüksel, İ., & Dağdeviren, M. (2010). Using the fuzzy analytic network process (ANP) for Balanced Scorecard (BSC): A case study for a manufacturing firm. Expert Systems with Applications, 37(2), 1270–1278. doi:10.1016/j.eswa.2009.06.002.CrossRef Yüksel, İ., & Dağdeviren, M. (2010). Using the fuzzy analytic network process (ANP) for Balanced Scorecard (BSC): A case study for a manufacturing firm. Expert Systems with Applications, 37(2), 1270–1278. doi:10.​1016/​j.​eswa.​2009.​06.​002.CrossRef
62.
Zurück zum Zitat Zadeh, L. A. (1965). Fuzzy sets. Information and Control, 8(3), 338–353.CrossRef Zadeh, L. A. (1965). Fuzzy sets. Information and Control, 8(3), 338–353.CrossRef
Metadaten
Titel
Security assessment framework for IoT service
verfasst von
Keon Chul Park
Dong-Hee Shin
Publikationsdatum
13.05.2016
Verlag
Springer US
Erschienen in
Telecommunication Systems / Ausgabe 1/2017
Print ISSN: 1018-4864
Elektronische ISSN: 1572-9451
DOI
https://doi.org/10.1007/s11235-016-0168-0

Weitere Artikel der Ausgabe 1/2017

Telecommunication Systems 1/2017 Zur Ausgabe

Neuer Inhalt