论文标题

默认情况下应有安全性:调查记者如何看待和应对物联网的风险

Security should be there by default: Investigating how journalists perceive and respond to risks from the Internet of Things

论文作者

Shere, Anjuli R. K., Nurse, Jason R. C., Flechais, Ivan

论文摘要

长期以来,记者一直是资源丰富的对手的身体和网络攻击的目标。物联网(物联网)设备可以说是通过针对性和广义网络物理剥削对记者威胁的新途径。这项研究包括三个部分:首先,我们采访了11位记者并进行了调查,并对5名新闻记者进行了调查,以确定记者通过物联网感知威胁的程度,尤其是通过消费者IoT设备。其次,我们调查了34位网络安全专家,以确定外行人是否以及如何应对物联网威胁。第三,我们将这些发现与评估记者对威胁的知识进行了比较,以及他们的保护机制是否有效地抵抗专家对物联网威胁的描述和预测。我们的结果表明,记者通常没有意识到与物联网相关的风险,也没有充分保护自己。这考虑了他们拥有IoT设备或进入基于IOT的环境(例如,在工作或家庭中)的情况。专家建议涵盖了即时和长期缓解方法,包括实际上具有技术性和社会政治性质的实际行动。但是,所有提议的个人缓解方法都可能是短期解决方案,34个(76.5%)的网络安全专家中有26种(76.5%)回应说,在接下来的五年内,公众将无法选择与IoT的交互。

Journalists have long been the targets of both physical and cyber-attacks from well-resourced adversaries. Internet of Things (IoT) devices are arguably a new avenue of threat towards journalists through both targeted and generalised cyber-physical exploitation. This study comprises three parts: First, we interviewed 11 journalists and surveyed 5 further journalists, to determine the extent to which journalists perceive threats through the IoT, particularly via consumer IoT devices. Second, we surveyed 34 cyber security experts to establish if and how lay-people can combat IoT threats. Third, we compared these findings to assess journalists' knowledge of threats, and whether their protective mechanisms would be effective against experts' depictions and predictions of IoT threats. Our results indicate that journalists generally are unaware of IoT-related risks and are not adequately protecting themselves; this considers cases where they possess IoT devices, or where they enter IoT-enabled environments (e.g., at work or home). Expert recommendations spanned both immediate and long-term mitigation methods, including practical actions that are technical and socio-political in nature. However, all proposed individual mitigation methods are likely to be short-term solutions, with 26 of 34 (76.5%) of cyber security experts responding that within the next five years it will not be possible for the public to opt-out of interaction with the IoT.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源