Repository logo
  • Log In
    New user? Click here to register.Have you forgotten your password?
University College Dublin
  • Colleges & Schools
  • Statistics
  • All of DSpace
  • Log In
    New user? Click here to register.Have you forgotten your password?
  1. Home
  2. College of Science
  3. School of Computer Science
  4. Computer Science Research Collection
  5. On the Automated Management of Security Incidents in Smart Spaces
 
  • Details
Options

On the Automated Management of Security Incidents in Smart Spaces

File(s)
FileDescriptionSizeFormat
Download paper.pdf57.82 MB
Author(s)
Alrimawi, Faeq 
Pasquale, Liliana 
Nuseibeh, Bashar 
Uri
http://hdl.handle.net/10197/11550
Date Issued
09 August 2019
Date Available
08T14:34:17Z September 2020
Abstract
The proliferation of smart spaces, such as smart buildings, is increasing opportunities for offenders to exploit the interplay between cyber and physical components, in order to trigger security incidents. Organizations are obliged to report security incidents to comply with recent data protection regulations. Organizations can also use incident reports to improve security of the smart spaces where they operate. Incident reporting is often documented in structured natural language. However, reports often do not capture relevant information about cyber and physical vulnerabilities present in a smart space that are exploited during an incident. Moreover, sharing information about security incidents can be difficult, or even impossible, since a report may contain sensitive information about an organization. In previous work, we provided a meta-model to represent security incidents in smart spaces. We also developed an automated approach to share incident knowledge across different organizations. In this paper we focus on incident reporting. We provide a System Editor to represent smart buildings where incidents can occur. Our editor allows us to represent cyber and physical components within a smart building and their interplay. We also propose an Incident Editor to represent the activities of an incident, including -for each activity- the target and the resources exploited, the location where the activity occurred, and the activity initiator. Building on our previous work, incidents represented using our editor can be shared across various organizations, and instantiated in different smart spaces to assess how they can re-occur. We also propose an Incident Filter component that allows viewing and prioritizing the most relevant incident instantiations, for example, involving a minimum number of activities. We assess the feasibility of our approach in assisting incident reporting using an example of a security incident that occurred in a research center.
Sponsorship
European Commission Horizon 2020
European Research Council
Science Foundation Ireland
Type of Material
Journal Article
Publisher
IEEE
Journal
IEEE Access
Volume
7
Start Page
111513
End Page
111527
Copyright (Published Version)
2019 IEEE
Keywords
  • Security

  • Organizations

  • Smart buildings

  • HVAC

  • Natural languages

  • Servers

DOI
10.1109/access.2019.2934221
Language
English
Status of Item
Peer reviewed
ISSN
2169-3536
This item is made available under a Creative Commons License
https://creativecommons.org/licenses/by-nc-nd/3.0/ie/
Owning collection
Computer Science Research Collection
Scopus© citations
10
Acquisition Date
Jan 27, 2023
View Details
Views
542
Last Month
10
Acquisition Date
Jan 28, 2023
View Details
Downloads
153
Last Week
1
Last Month
1
Acquisition Date
Jan 28, 2023
View Details
google-scholar
University College Dublin Research Repository UCD
The Library, University College Dublin, Belfield, Dublin 4
Phone: +353 (0)1 716 7583
Fax: +353 (0)1 283 7667
Email: mailto:research.repository@ucd.ie
Guide: http://libguides.ucd.ie/rru

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Cookie settings
  • Privacy policy
  • End User Agreement