Back to results

UNSW, Sydney

The internet of things : securing devices and user data

Abstract

dc:description

The Internet of Things (IoT) is a reality technology which has provided tremendous opportunities for consumers and businesses of all kinds. As IoT is becoming increasingly common and more devices are appearing into market, security becomes a major concern. IoT devices and applications are notoriously insecure which pose emergent threats to consumers’ assets, well-being, and privacy. Thus, it is crucial to ensure security properties are met in IoT systems which often handle a lot of sensitive data. Developing secure and trustworthy IoT systems is hard and challenging due to IoT environment characteristics by nature such as resource constraints, heterogeneity architectures, and wireless communications. This thesis investigates security and privacy concerns in IoT systems and introduces three novel mechanisms to mitigate IoT security risks. To this end, we devise and study novel schemes and mechanisms and investigate how security properties of IoT systems can be practically improved on resource-constrained devices and cloud backend. In the first part of the thesis, we implemented and evaluated an intrusion detection and mitigation framework, called IoT-IDM, providing a network-level protection for IoT devices within the home. This framework leverages Software-defined Networking (SDN) technology to monitor the activities of intended IoT devices and block intruders once malicious activities detected. The second part of the thesis focuses on designing a security mechanism, called IoT- NetSec, to enforce device availability requirement using a policy-based approach. IoT- NetSec augments IoT-IDM and takes advantages of SDN capability in flow counting and statistics collection to detect network services attacks such as DoS, port scanning and DDoS attacks. Next, this thesis introduces and evaluates a static permission analysis tool, called PGFit, to ensure confidentiality property of user IoT data stored on cloud backend by performing over-privilege analysis in third-party apps built on top of IoT programming frameworks. As a representative, we have applied PGFit on a popular IoT programming framework for health and fitness data, Google Fit. Our investigation with PGFit showed that a considerable number of Google Fit-enabled apps are overprivileged. PGFit can be used as a quality assurance tool for IoT app developers and a privacy checker for end-users.

Degree

thesis:*
Grantor dc:publisher
UNSW, Sydney
Year dc:date
2019

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Nobakht, Mehdi

Subjects

dc:subject × 4

Rights

dc:rights
Statement dc:rights
  • open access
  • CC BY-NC-ND 3.0
  • free_to_read
Language dc:language
EN

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:unsworks.library.unsw.edu.au:1959.4/61962

Chain of custody

source
Harvested from
University of New South Wales
Base URL
unsworks.unsw.edu.au/oai/provider
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
related terms
citation

Nobakht, Mehdi. The internet of things : securing devices and user data. UNSW, Sydney, 2019. http://hdl.handle.net/1959.4/61962