Technological advances have enabled multiple countries to consider implementing Smart City Infrastructure to provide in-depth insights into different data points and enhance the lives of citizens. Unfortunately, these new technological implementations also entice adversaries and cybercriminals to execute cyber-attacks and commit criminal acts on these modern infrastructures. Given the borderless nature of cyber attacks, varying levels of understanding of smart city infrastructure and ongoing investigation workloads, law enforcement agencies and investigators would be hard-pressed to respond to these kinds of cybercrime. Without an investigative capability by investigators, these smart infrastructures could become new targets favored by cybercriminals. To address the challenges faced by investigators, we propose a common definition of smart city infrastructure. Based on the definition, we utilize the STRIDE threat modeling methodology and the Microsoft Threat Modeling Tool to identify threats present in the infrastructure and create a threat model which can be further customized or extended by interested parties. Next, we map offences, possible evidence sources and types of threats identified to help investigators understand what crimes could have been committed and what evidence would be required in their investigation work. Finally, noting that Smart City Infrastructure investigations would be a global multi-faceted challenge, we discuss technical and legal opportunities in digital forensics on Smart City Infrastructure.


翻译:技术进步使得多个国家开始考虑建设智慧城市基础设施,以深入洞察不同数据点并提升公民生活质量。然而,这些新型技术实施也诱使攻击者和网络犯罪分子对这些现代基础设施发动网络攻击并实施犯罪行为。鉴于网络攻击的无国界特性、各方对智慧城市基础设施认知水平的差异以及持续增长的调查工作量,执法机构和调查人员将难以有效应对此类网络犯罪。若调查人员缺乏调查能力,这些智慧基础设施可能成为网络犯罪分子青睐的新目标。为应对调查人员面临的挑战,我们首先提出智慧城市基础设施的通用定义。基于该定义,我们运用STRIDE威胁建模方法论与Microsoft威胁建模工具,识别基础设施中存在的威胁,并构建可被相关方进一步定制或扩展的威胁模型。随后,我们映射犯罪类型、潜在证据来源及威胁分类,以帮助调查人员理解可能发生的犯罪行为及调查工作中所需的证据类型。最后,鉴于智慧城市基础设施调查将成为全球性的多维度挑战,我们探讨了智慧城市基础设施数字取证领域的技术机遇与法律机遇。

0
下载
关闭预览

相关内容

专知会员服务
19+阅读 · 2020年9月6日
[综述]深度学习下的场景文本检测与识别
专知会员服务
78+阅读 · 2019年10月10日
隐私沙盒: 开发者预览版 5 已经发布!
谷歌开发者
0+阅读 · 2022年10月17日
直击RSAC2022:网络资产攻击面管理(CAASM)成安全新解法
CCF计算机安全专委会
0+阅读 · 2022年6月10日
Gartner 报告:人工智能的现状与未来
InfoQ
14+阅读 · 2019年11月29日
Hierarchically Structured Meta-learning
CreateAMind
27+阅读 · 2019年5月22日
大数据 | 顶级SCI期刊专刊/国际会议信息7条
Call4Papers
10+阅读 · 2018年12月29日
A Technical Overview of AI & ML in 2018 & Trends for 2019
待字闺中
18+阅读 · 2018年12月24日
【推荐】RNN/LSTM时序预测
机器学习研究会
25+阅读 · 2017年9月8日
国家自然科学基金
1+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
1+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
3+阅读 · 2013年12月31日
国家自然科学基金
3+阅读 · 2011年12月31日
国家自然科学基金
0+阅读 · 2009年12月31日
Arxiv
0+阅读 · 2023年5月3日
Arxiv
30+阅读 · 2021年7月7日
VIP会员
最新内容
《异构人类团队的协作决策过程混合建模研究》
专知会员服务
1+阅读 · 7分钟前
博士论文 | 面向大模型推理的内存高效算法
专知会员服务
2+阅读 · 7月27日
美空军新型反无人机部队初探
专知会员服务
7+阅读 · 7月27日
《防空交战流程的概率建模研究》
专知会员服务
10+阅读 · 7月27日
ICML 2026 教程 | 数值优化理论还重要吗?
专知会员服务
6+阅读 · 7月26日
ICM 2026 | 陶哲轩:人工智能时代的数学
专知会员服务
9+阅读 · 7月26日
相关VIP内容
专知会员服务
19+阅读 · 2020年9月6日
[综述]深度学习下的场景文本检测与识别
专知会员服务
78+阅读 · 2019年10月10日
相关资讯
隐私沙盒: 开发者预览版 5 已经发布!
谷歌开发者
0+阅读 · 2022年10月17日
直击RSAC2022:网络资产攻击面管理(CAASM)成安全新解法
CCF计算机安全专委会
0+阅读 · 2022年6月10日
Gartner 报告:人工智能的现状与未来
InfoQ
14+阅读 · 2019年11月29日
Hierarchically Structured Meta-learning
CreateAMind
27+阅读 · 2019年5月22日
大数据 | 顶级SCI期刊专刊/国际会议信息7条
Call4Papers
10+阅读 · 2018年12月29日
A Technical Overview of AI & ML in 2018 & Trends for 2019
待字闺中
18+阅读 · 2018年12月24日
【推荐】RNN/LSTM时序预测
机器学习研究会
25+阅读 · 2017年9月8日
相关基金
国家自然科学基金
1+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
1+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
0+阅读 · 2013年12月31日
国家自然科学基金
3+阅读 · 2013年12月31日
国家自然科学基金
3+阅读 · 2011年12月31日
国家自然科学基金
0+阅读 · 2009年12月31日
Top
微信扫码咨询专知VIP会员