Authors:
Rauli Kaksonen
1
;
Kimmo Halunen
1
;
2
;
Marko Laakso
1
and
Juha Röning
1
Affiliations:
1
University of Oulu, Oulu, Finland
;
2
National Defence University of Finland, Department of Military Technology, Finland
Keyword(s):
IoT, Security standard, Testing, Automation, Security tools, ETSI EN 303 645, ETSI TS 103 701
Abstract:
Cybersecurity standards play a vital role in safeguarding the Internet of Things (IoT). Currently, standard compliance is assessed through manual reviews by security experts, a process which cost and delay is often too high. This research delves into the potential of automating IoT security standard testing, focusing on the ETSI TS 103 701 test specification for the ETSI EN 303 645 standard. From the test specification, 56 tests are relevant for the network attack threat model and considered for automation. The results are promising: basic network security tools can automate 52% of these tests, and advanced tools can push that number up to 70%. For full test coverage, custom tooling is required. The approach is validated by creating a test verdict automation for a real-world IoT product. Test automation is an investment, but the results indicate it can streamline security standard verification, especially for product updates and variants. The automation can use data from other testi
ng activities to reduce effort. Automating the security standard testing would enable the certification of a large number of IoT products for their lifetime.
(More)