Edge computing brings processing and storage capabilities closer to the data sources, to reduce network latency, save bandwidth, and preserve data locality. Despite the clear benefits, this paradigm brings unprecedented cyber risks due to the combination of the security issues and challenges typical of cloud and Internet of Things (IoT) worlds. Notwithstanding an increasing interest in edge security by academic and industrial communities, there is still no discernible industry consensus on edge computing security best practices, and activities like threat analysis and countermeasure selection are still not well established and are completely left to security experts.In order to cope with the need for a simplified yet effective threat modeling process, which is affordable in presence of limited security skills and economic resources, and viable in modern development approaches, in this paper, we propose an automated threat modeling and countermeasure selection strategy targeting edge computing systems. Our approach leverages a comprehensive system model able to describe the main involved architectural elements and the associated data flow, with a focus on the specific properties that may actually impact on the applicability of threats and of associated countermeasures.

Toward automated threat modeling of edge computing systems / Casola V.; Benedictis A.D.; Mazzocca C.; Montanari R.. - ELETTRONICO. - (2021), pp. 135-140. (Intervento presentato al convegno 2021 IEEE International Conference on Cyber Security and Resilience, CSR 2021 tenutosi a Rhodes, Greece nel 26-28 July 2021) [10.1109/CSR51186.2021.9527937].

Toward automated threat modeling of edge computing systems

Mazzocca C.;Montanari R.
2021

Abstract

Edge computing brings processing and storage capabilities closer to the data sources, to reduce network latency, save bandwidth, and preserve data locality. Despite the clear benefits, this paradigm brings unprecedented cyber risks due to the combination of the security issues and challenges typical of cloud and Internet of Things (IoT) worlds. Notwithstanding an increasing interest in edge security by academic and industrial communities, there is still no discernible industry consensus on edge computing security best practices, and activities like threat analysis and countermeasure selection are still not well established and are completely left to security experts.In order to cope with the need for a simplified yet effective threat modeling process, which is affordable in presence of limited security skills and economic resources, and viable in modern development approaches, in this paper, we propose an automated threat modeling and countermeasure selection strategy targeting edge computing systems. Our approach leverages a comprehensive system model able to describe the main involved architectural elements and the associated data flow, with a focus on the specific properties that may actually impact on the applicability of threats and of associated countermeasures.
2021
2021 IEEE International Conference on Cyber Security and Resilience (CSR)
135
140
Toward automated threat modeling of edge computing systems / Casola V.; Benedictis A.D.; Mazzocca C.; Montanari R.. - ELETTRONICO. - (2021), pp. 135-140. (Intervento presentato al convegno 2021 IEEE International Conference on Cyber Security and Resilience, CSR 2021 tenutosi a Rhodes, Greece nel 26-28 July 2021) [10.1109/CSR51186.2021.9527937].
Casola V.; Benedictis A.D.; Mazzocca C.; Montanari R.
File in questo prodotto:
File Dimensione Formato  
IEEECSR2021.pdf

accesso aperto

Tipo: Postprint
Licenza: Licenza per accesso libero gratuito
Dimensione 475.79 kB
Formato Adobe PDF
475.79 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11585/865847
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? 2
social impact