TY - GEN
T1 - A Mobile Application for Security Assessment Towards the Internet of Thing Devices
AU - Visoottiviseth, Vasaka
AU - Kotarasu, Chatchawan
AU - Cheunprapanusorn, Niramit
AU - Chamornmarn, Thitiwut
N1 - Publisher Copyright:
© 2019 IEEE.
PY - 2019/11
Y1 - 2019/11
N2 - The Internet of Things or IoT is one of the disruptive technologies which has been grown its attention rapidly. However, because of the neglect of security awareness of vendors and users, this technology is vulnerable to be leveraged as a cyber weapon by malicious attackers. Therefore, we develop an IoT security solution, called MASai, which encourages general users who are not expert in cybersecurity to perform penetration testing on their IoT devices so that they can be aware of these problems and gain security awareness. MASai is comprised of MASai application on Android phones, MASai box, and MASai server. MASai application allows users to execute penetration testing on targeted IoT devices and targeted mobile applications controlling the devices throughouta mobile interface. MASai application works along with MASai Box, a Raspberry Pi embedded with Kali Linux distribution, to find vulnerabilities of the targeted IoT devices. Several techniques such as information gathering, wireless attacks, and vulnerability scanning are integrated for the assessment. MASai server allows users to perform Android reverse engineering and static code analysis for the mobile application security assessment. All vulnerability assessments and penetration testing are based on OWASP Top 10 IoT Vulnerabilities and OWASP Mobile Top 10. By using MASai, we expect users to gain security awareness and can prevent the unexpected consequences of IoT technology.
AB - The Internet of Things or IoT is one of the disruptive technologies which has been grown its attention rapidly. However, because of the neglect of security awareness of vendors and users, this technology is vulnerable to be leveraged as a cyber weapon by malicious attackers. Therefore, we develop an IoT security solution, called MASai, which encourages general users who are not expert in cybersecurity to perform penetration testing on their IoT devices so that they can be aware of these problems and gain security awareness. MASai is comprised of MASai application on Android phones, MASai box, and MASai server. MASai application allows users to execute penetration testing on targeted IoT devices and targeted mobile applications controlling the devices throughouta mobile interface. MASai application works along with MASai Box, a Raspberry Pi embedded with Kali Linux distribution, to find vulnerabilities of the targeted IoT devices. Several techniques such as information gathering, wireless attacks, and vulnerability scanning are integrated for the assessment. MASai server allows users to perform Android reverse engineering and static code analysis for the mobile application security assessment. All vulnerability assessments and penetration testing are based on OWASP Top 10 IoT Vulnerabilities and OWASP Mobile Top 10. By using MASai, we expect users to gain security awareness and can prevent the unexpected consequences of IoT technology.
KW - Android Application Security
KW - internet of Things
KW - mobile Application
KW - penetration Testing
KW - security Assessment
UR - https://www.scopus.com/pages/publications/85084642694
U2 - 10.1109/ACDT47198.2019.9072921
DO - 10.1109/ACDT47198.2019.9072921
M3 - Conference contribution
AN - SCOPUS:85084642694
T3 - Proceedings of the 2019 IEEE 6th Asian Conference on Defence Technology, ACDT 2019
SP - 1
EP - 7
BT - Proceedings of the 2019 IEEE 6th Asian Conference on Defence Technology, ACDT 2019
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 6th IEEE Asian Conference on Defence Technology, ACDT 2019
Y2 - 13 November 2019 through 15 November 2019
ER -