Wireless Network Security Spring 2015

Similar documents
Esri and GIS Education

US National Spatial Data Infrastructure A Spatial Framework for Governance and Policy Development to Enable a Location-Based Digital Ecosystem

Lesson 16: Technology Trends and Research

WeatherCloud Hyper-Local Global Forecasting All rights reserved. Fathym, Inc.

ArcGIS is Advancing. Both Contributing and Integrating many new Innovations. IoT. Smart Mapping. Smart Devices Advanced Analytics

1 Introduction. Station Type No. Synoptic/GTS 17 Principal 172 Ordinary 546 Precipitation

Portal for ArcGIS: An Introduction

DIGITAL TWINS W A Z U G D e c e m b e r

WordPress and CRM. Match Made In Heaven... or Hell?

Demographic Data in ArcGIS. Harry J. Moore IV

Web GIS: Architectural Patterns and Practices. Shannon Kalisky Philip Heede

1 Descriptions of Function

Portal for ArcGIS: An Introduction. Catherine Hynes and Derek Law

Web GIS Deployment for Administrators. Vanessa Ramirez Solution Engineer, Natural Resources, Esri

Enabling Web GIS. Dal Hunter Jeff Shaner

Securing the Web of Things

Migration to the New BI360

Wireless Network Security Spring 2016

Syllabus Structure for Computer Science and Systems Engineering

Case Study Saginaw County, Michigan

Leveraging Web GIS: An Introduction to the ArcGIS portal

MeteoGroup RoadMaster. The world s leading winter road weather solution

Telecommunication Services Engineering (TSE) Lab. Chapter IX Presence Applications and Services.

Kenneth Graziano Senior Technical Consultant Unified Communications

Device Specifications

TRAITS to put you on the map

USEPA's Comprehensive Geospatial Information Sharing Framework

ArcGIS Urban: An Introduction. Lisa Staehli ArcGIS Urban Team Product Development Brooks Patrick ArcGIS Urban Team Business Development

Introduction to Portal for ArcGIS

personal weather station

Geo-Enabling Mountain Bike Trail Maintenance:

Syllabus. Physics 0847, How Things Work Section II Fall 2014

CORPORATE PROFILE MEVATRON SOLUTIONS PRIVATE LIMITED.

GIS Capability Maturity Assessment: How is Your Organization Doing?

Data Aggregation with InfraWorks and ArcGIS for Visualization, Analysis, and Planning

Introduction to Portal for ArcGIS. Hao LEE November 12, 2015

Working with ArcGIS Online

Open spatial data infrastructure

Web GIS & ArcGIS Pro. Zena Pelletier Nick Popovich

UC Davis - Student Community Center

Web GIS Patterns and Practices

Spatial Data Science. Soumya K Ghosh

Land Use in the context of sustainable, smart and inclusive growth

Founding of a Grower-based Weather/Pest Information Network to Aid IPM Adoption

GIS for Crime Analysis. Building Better Analysis Capabilities with the ArcGIS Platform

XXIII CONGRESS OF ISPRS RESOLUTIONS

Edge Computing and the Next Generation Central Office

CPSC 531 Systems Modeling and Simulation FINAL EXAM

ArcGIS Enterprise: What s New. Philip Heede Shannon Kalisky Melanie Summers Sam Williamson

ArcGIS Deployment Pattern. Azlina Mahad

ARGUS.net IS THREE SOLUTIONS IN ONE

Introduction to ArcGIS Maps for Office. Greg Ponto Scott Ball

OFWIM 2017 Annual Conference What Does Web GIS Really Mean for Fish and Wildlife Agencies?

Better Weather Data Equals Better Results: The Proof is in EE and DR!

The Light Ghost. We were contacted by T.A.P.S (The Atlantic Paranormal Society), they forwarded the following e mail:

NOAA Surface Weather Program

USDOT Applications Utilizing RWIS

Building a National Data Repository

PDF / LA CROSSE TECHNOLOGY WEATHER STATION RESET EBOOK

B.Tech (Electronics & Computer Engineering)

Integrated Electricity Demand and Price Forecasting

Your Perfect 3D World (BIM and GIS Integrated)

Introduction to Spatial Analysis in ArcGIS Online. Jian Lange, Vicki Lynn Cove

Assembly and Operation Manual. April 2016

Weather Company Energy and Power Products

CSE 241 Class 1. Jeremy Buhler. August 24,

Complete Weather Intelligence for Public Safety from DTN

Compensation Planning Application

GIS (GEOGRAPHIC INFORMATION SYSTEMS)

Understanding the Impact and Value of Esri s Utility Network for Network Management

ADVANCED WEATHER STATION ARCHIVE

Mobility Analytics through Social and Personal Data. Pierre Senellart

Reimaging GIS: Geographic Information Society. Clint Brown Linda Beale Mark Harrower Esri

You are Building Your Organization s Geographic Knowledge

United States Multi-Hazard Early Warning System

Decision Support Part 1: Tools to aid travel planning

Moroccan lightning detection network, topology, performance and management of the network

DP Project Development Pvt. Ltd.

Semantic Geospatial Data Integration and Mining for National Security

REPORT ON INVESTMENTS

DANIEL WILSON AND BEN CONKLIN. Integrating AI with Foundation Intelligence for Actionable Intelligence

The Kentucky Mesonet: Entering a New Phase

Introduction to Google Drive Objectives:

NovaToast SmartVision Project Requirements

Reference: 4880(DOP.ADA)1136 Subject: Survey on the integration of geographic information systems into postal address development

Designing Information Devices and Systems I Summer 2017 D. Aranki, F. Maksimovic, V. Swamy Homework 5

Welcome to Physics 161 Elements of Physics Fall 2018, Sept 4. Wim Kloet

UAS Applications Tim McCarthy, NUI Maynooth INFOMAR 9 th Oct

Tornado Drill Exercise Plan (EXPLAN)

SpyMeSat Mobile App. Imaging Satellite Awareness & Access

P R O G N O S T I C S

NOAA S2S Planning. Dave DeWitt Fred Toepfer

The Significance and Role of GIS and CSDI in Smart City Development

NOAA s Big Data Project: Vision and Approach

Benefits of Applying Predictive Intelligence to the Space Situational Awareness (SSA) Mission

CS 347 Parallel and Distributed Data Processing

Jun Zhang Department of Computer Science University of Kentucky

CLICK HERE TO KNOW MORE

Perform. Xcel. Lead. Presenter. Raghavendran S. GM Technical (GIS)

AgWeatherNet A Tool for Making Decisions Based on Weather

Transcription:

Wireless Network Security Spring 2015 Patrick Tague Class #20 IoT Security & Privacy 1

Class #20 What is the IoT? the WoT? IoT Internet, WoT Web Examples of potential security and privacy problems in current and near-future IoT usage scenarios Architectural changes that may address these issues 2

The Internet of Things is? What kind of things are we interested in connecting to the internet? My computer, laptop, and phone are all things has the IoT been around for 40 years? If I put a WiFi chip in a sensor and stick the sensor on the wall, did I just create the Internet of Things? When my Nest thermostat controls my heater using data from the cloud, is that the Internet of Things? My favorite IoT quote: That's not the Internet of Things, that's the Internet with Things. 3

So, the Internet of Things is? It's complicated. Everyone has their own definition. Most are something to the effect of: Allowing embedded things to collaborate to provide some sort of service to users, apps, or other things Apps can get data from some things, process the data using other things, make decisions using other things, and affect the real world using other things Many of these things are wireless 4

Example 1: Industrial IoT 5

Maintenance / service provider Final product assembler... Org. A Org. N Org. B... 6

Maintenance / service provider Final product assembler... Org. A Org. N Org. B ALERT: Broken robot arm!... 7

Maintenance / service provider Final product assembler... Org. A Org. N Org. B ALERT: Broken robot arm! Security challenge: resource... has to manage an limited device external secure session 8

Maintenance / service provider Final product assembler... Org. A Org. N Org. B ALERT: Broken robot arm! Policy challenge: how to...which providers/orgs regulate can access data? 9

Maintenance / service provider Final product assembler Org. B challenge:... Scalability/security Org. N service orchestrator has to manage all relevant device sessions Org. A... 10

Example 2: Residential IoT 11

Weather Forecast, Calendar, Scheduled events Analytics & Control Motion Light Sound Air-flow Humidity... 12

Analytics & Control Service provider's operational domain 13

Analytics & Control Customer's physical domain 14

Analytics & Control Potential private data leakage Customer's physical domain 15

Example 3: Urban/Civil IoT 16

17

Security challenge: how do devices discover each other and verify who they discovered? 18

Security challenge: how to efficiently establish secure connections with other devices? 19

Security challenge: how to validate measurements from sources (e.g., sensors, beacons)? 20

Data-Centric Issues Who owns the data? Also, who determines who owns the sensor data? How to track where data is created, transported, analyzed, stored, used as input, etc.? What data is needed? Does your application need raw sensor data as input, or will something else suffice? What information is conveyed in the data? What can your application learn from my data? 21

When is the information more than the data? 22

Occupancy Occupancy = #people in a room A sensor aggregate that is very valuable for green HVAC Rm101 Rm103 Occ = 1 Occ = 1 Rm105 Occ = 2 Hallway, Occ = 0 Rm100 Occ = 0 Rm102 Occ = 1 Rm107 Occ = 4 Rm104 Rm106 Occ = 0 Occ = 1 It's tempting to say that occupancy is privacypreserving (in fact, many people have said it) 23

Occupancy + Context Rm101 Rm103 Occ = 1 Occ = 1 Rm105 Occ = 2 Rm107 Occ = 4 Hallway, Occ = 0 Rm100 Occ = 0 Rm102 Occ = 1 Rm104 Rm106 Occ = 0 Occ = 1 Directory: Rm100: Aaron's office Rm101: Beth's office Rm102: Carlos's office Rm103: Dennis's office Rm104: Evelyn's office Rm105: Shared lab Rm106: Kitchen Rm107: Boardroom 24

Dynamic Occupancy Rm101 Ot = 1 Rm103 Ot = 1 Rm105 Ot = 2 Ot+1 = 0 Ot+1 = 1 Ot+1 = 2 Rm107 Ot = 4 Hallway, Ot = 0, Ot+1 = 0 Rm100 Ot = 0 Rm102 Ot = 1 Rm104 Ot = 0 Rm106 Ot = 1 Ot+1 = 0 Ot+1 = 2 Ot+1 = 0 Ot+1 = 1 Ot+1 = 4 Directory: Rm100: Rm101: Rm102: Rm103: Rm104: Rm105: Rm106: Rm107: Aaron's office Beth's office Carlos's office Dennis's office Evelyn's office Shared lab Kitchen Boardroom 25

Occupancy Tracking Sufficiently fine-grained occupancy data permits location trace reconstruction of building users Context information permits labeling of location traces with user identity Occupancy Traces 1 1 0 1 2 2 0 1 2 4 1 1 1 3 Machine Learning M Labeled Location Traces u1: 202 Rooms 200 201 202 203 205 Floor Plan 2 Pantry 209 208 207 206 Toilet 3 T Office Users u1 u2 Info. Office 202 207 Timeline: 1 un: 201 202 209 202 208 un 206 26

Accuracy Privacy Risk Augsburg benchmark dataset w/ synthetic data; Estimation using FHMM + modified Viterbi algorithm 27

How can we address these issues? 28

Analytics & Control Potential private data leakage Customer's physical domain 29

Application Provider Higher-Level Analytics Shared with the Provider Local app Analytics & Control Operated by the Customer Local cloud can provide connectivity, discovery, mgmt, mediation, etc. as services 30

A Few Considerations Local cloud resources can use trustworthy computing principles to securely house 3rd-party software (just like a mobile phone) Mediating gateway can actively control information flow between internal devices and third-party resources Active migration within the local domain can help with (near-)real-time CPS requirements 31

Migration 32

How could two orgs collaborate in a constructive, efficient, privacypreserving, manner? Federation Org. A Org. B 33

Generalized IoT Domain Model Intra-domain: everything is managed locally/privately by the domain controller Org. A Inter-domain: domain controllers initiate, mediate, and manage interactions 34

Take-Away Points IoT Internet (or WoT Web) Domain federation/mediation model allows for finer-grained control of collaboration, sharing, etc. common to IoT applications Domain model comes with its own challenges, so still a lot of work to be done 35

Apr 2: Progress Presentations Apr 7: Exam Apr 9: Telecom Security & Privacy 36