论文标题

通过威胁建模来确定智能城市基础设施中的威胁,网络犯罪和数字法医机会

Identifying Threats, Cybercrime and Digital Forensic Opportunities in Smart City Infrastructure via Threat Modeling

论文作者

Tok, Yee Ching, Chattopadhyay, Sudipta

论文摘要

技术进步使多个国家能够考虑实施智能城市基础设施,以深入了解不同的数据点并改善公民的生活。不幸的是,这些新的技术实施也诱使对手和网络犯罪分子执行网络攻击,并对这些现代基础设施犯下犯罪行为。鉴于网络攻击的无边界性质,对智能城市基础设施和正在进行的调查工作量的理解水平不同,执法机构和调查人员将很难对这些类型的网络犯罪做出反应。没有研究人员的调查能力,这些智能基础设施可能会成为网络犯罪分子所青睐的新目标。 为了应对调查人员面临的挑战,我们提出了智能城市基础设施的共同定义。基于定义,我们利用步幅威胁建模方法和Microsoft威胁建模工具来识别基础架构中存在的威胁,并创建一个威胁模型,该模型可以由兴趣的各方进一步定制或扩展。接下来,我们绘制犯罪,可能确定的证据来源和类型的威胁,以帮助调查人员了解可能犯下的犯罪以及他们的调查工作中需要什么证据。最后,注意到智能城市基础设施调查将是全球多方面的挑战,我们讨论了智能城市基础设施数字取证的技术和法律机会。

Technological advances have enabled multiple countries to consider implementing Smart City Infrastructure to provide in-depth insights into different data points and enhance the lives of citizens. Unfortunately, these new technological implementations also entice adversaries and cybercriminals to execute cyber-attacks and commit criminal acts on these modern infrastructures. Given the borderless nature of cyber attacks, varying levels of understanding of smart city infrastructure and ongoing investigation workloads, law enforcement agencies and investigators would be hard-pressed to respond to these kinds of cybercrime. Without an investigative capability by investigators, these smart infrastructures could become new targets favored by cybercriminals. To address the challenges faced by investigators, we propose a common definition of smart city infrastructure. Based on the definition, we utilize the STRIDE threat modeling methodology and the Microsoft Threat Modeling Tool to identify threats present in the infrastructure and create a threat model which can be further customized or extended by interested parties. Next, we map offences, possible evidence sources and types of threats identified to help investigators understand what crimes could have been committed and what evidence would be required in their investigation work. Finally, noting that Smart City Infrastructure investigations would be a global multi-faceted challenge, we discuss technical and legal opportunities in digital forensics on Smart City Infrastructure.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源