A Network Service for Preventing Data Leakage from IoT Cloud-assisted Equipment

ISCC(2019)

引用 1|浏览57
暂无评分
摘要
The fact that most IoT solutions are provided by third parties, along with the pervasiveness of the collected data, raises privacy and security concerns. There is a need to verify which data is being sent to the third party, as well as preventing those channels from becoming an exploitation avenue. We propose to use existing API definition languages to create contracts which define the data that can be transmitted, their format and constraints. To verify the compliance with these contracts, we propose a Network Service architecture which validates REST-like API requests/responses against a Swagger schema. We deal with encrypted traffic using an Service Function Chaining (SFC)-enabled Man-in-the-Middle (MITM), allowing verifications in "real-time." We devised a Proof of Concept and showed that we were able to detect (and stop) contract violations.
更多
查看译文
关键词
data leakage,IoT cloud-assisted equipment,API definition languages,contracts,Network Service architecture,service function chaining,contract violations,man-in-the-middle,SFC,MITM,REST-like API requests-responses,Swagger schema
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要