Главная
Study mode:
on
1
Intro
2
Agenda
3
Process Challenges
4
Technical Challenges
5
Holistic Security & Privacy Process
6
Security Topics
7
Hardware & Firmware Security Paradigms
8
SW Security Paradigms: application SW
9
Communication Protocols
10
Ecosystem security challenges
11
Demo 1: Ecosystem overview
12
Device communication
13
The Problem - Prelude
14
Example - Wearable Ecosystem 1
15
Demo 2: Ecosystem overview
16
Target : Sign-up and Profile pages
17
Exploit Scenario: The attack
18
Victim - logs in
19
Attacker's c&c
20
Access to admin portal
21
Privacy & Data Access Laws
22
Quantifying Privacy Vulnerabilities
23
Summary
Description:
Explore the challenges and solutions for securing Internet of Things (IoT) devices in this AppSecUSA 2018 conference talk. Dive into the Security & Privacy Development Lifecycle (SPDL), an agile framework tailored for IoT platforms that addresses both process and technical challenges. Learn about the shortcomings of traditional Security Development Lifecycle (SDL) methodologies when applied to IoT and how SPDL overcomes them. Discover the importance of privacy in IoT development, including compliance with regulations like GDPR, and understand the proposed privacy vulnerability scoring framework (CPVSS) for measuring and prioritizing privacy breaches. Gain insights from industry experts on securing various IoT devices, from smart fridges to pacemakers, and explore topics such as hardware and firmware security paradigms, software security, communication protocols, and ecosystem security challenges. Watch demonstrations of ecosystem overviews and exploit scenarios to better understand the complexities of IoT security. Read more

IoT Security - Ecosystem, Interoperability and Standards

OWASP Foundation
Add to list