|
|
Line 10: |
Line 10: |
| ''The OWASP Internet of Things Project is designed to help manufacturers, developers, and consumers better understand the security issues associated with the Internet of Things, and to enable users in any context to make better security decisions when building, deploying, or assessing IoT technologies''. | | ''The OWASP Internet of Things Project is designed to help manufacturers, developers, and consumers better understand the security issues associated with the Internet of Things, and to enable users in any context to make better security decisions when building, deploying, or assessing IoT technologies''. |
| | | |
− | The project looks to define a structure for various IoT sub-projects such as Attack Surface Areas, Testing Guides, Tools, and Top Vulnerabilities. | + | The project looks to define a structure for various IoT sub-projects separated into the following categories - Seek & Understand, Validate & Test, and Governance. |
| | | |
| ==Updated!== | | ==Updated!== |
Line 146: |
Line 146: |
| |} | | |} |
| | | |
− | = IoT Top 10 = | + | = Seek & Understand = |
| + | |
| + | == IoT Top 10 == |
| <div style="width:100%;height:160px;border:0,margin:0;overflow: hidden;">[[File:OWASP_Project_Header.jpg|link=]]</div> | | <div style="width:100%;height:160px;border:0,margin:0;overflow: hidden;">[[File:OWASP_Project_Header.jpg|link=]]</div> |
| | | |
Line 182: |
Line 184: |
| * [[Top 10 2014-I10 Poor Physical Security|I10 Poor Physical Security]] | | * [[Top 10 2014-I10 Poor Physical Security|I10 Poor Physical Security]] |
| | | |
− | = OWASP IoT Top 10 2018 Mapping Project = | + | == OWASP IoT Top 10 2018 Mapping Project == |
| {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- | | {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- |
| | style="border-right: 1px dotted gray;padding-right:25px;" valign="top" | | | | style="border-right: 1px dotted gray;padding-right:25px;" valign="top" | |
Line 1,292: |
Line 1,294: |
| | | |
| |} | | |} |
− | =ICS/SCADA=
| |
− | <div style="width:100%;height:160px;border:0,margin:0;overflow: hidden;">[[File:OWASP_Project_Header.jpg|link=]]</div>
| |
− | {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
| |
− | | valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |
| |
− | ==ICS/SCADA Project==
| |
− | The OWASP ICS/SCADA Top 10 software weaknesses are as follows:
| |
− | {| class="wikitable" border="1" style="text-align: left"
| |
− | !Rank and ID
| |
− | !Title
| |
− | |-
| |
− | |'''1 - CWE-119'''
| |
− | |
| |
− | *Improper Restriction of Operations within the Bounds of a Memory Buffer
| |
− | |-
| |
− | |'''2 - CWE-20'''
| |
− | |
| |
− | *Improper Input Validation
| |
− | |-
| |
− | |'''3 - CWE-22'''
| |
− | |
| |
− | *Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| |
− | |-
| |
− | |'''4 - CWE-264'''
| |
− | |
| |
− | *Permissions, Privileges, and Access Controls
| |
− | |-
| |
− | |'''5 - CWE-200'''
| |
− | |
| |
− | *Information Exposure
| |
− | |-
| |
− | |'''6 - CWE-255'''
| |
− | |
| |
− | *Credentials Management
| |
− | |-
| |
− | |'''7 - CWE-287'''
| |
− | |
| |
− | *Improper Authentication
| |
− | |-
| |
− | |'''8 - CWE-399'''
| |
− | |
| |
− | *Resource Management Errors
| |
− | |-
| |
− | |'''9 - CWE-79'''
| |
− | |
| |
− | *Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| |
− | |-
| |
− | |'''10 - CWE-189'''
| |
− | |
| |
− | *Numeric Errors
| |
− | |-
| |
− | |}{{Social Media Links}}
| |
− | | valign="top" style="padding-left:25px;width:300px;border-right: 1px dotted gray;padding-right:25px;" |
| |
− | ==What is the ICS/SCADA Project?==
| |
− | The ICS/SCADA Project provides:
| |
− | *A list of the Top 10 most dangerous software weaknesses
| |
− | ==Project Leaders==
| |
− | *NJ Ouchn
| |
− | ==Related Projects==
| |
− | *[[OWASP Mobile Security Project|OWASP Mobile Security]]
| |
− | *[[OWASP Top Ten Project|OWASP Web Top 10]]
| |
− | ==Collaboration==
| |
− | [https://owasp-iot-security.slack.com/ The Slack Channel]
| |
− | ==Quick Download==
| |
− | *Coming Soon
| |
− | ==News and Events==
| |
− | *Coming Soon
| |
− | |}<div style="width:100%;height:160px;border:0,margin:0;overflow: hidden;"></div>
| |
− |
| |
− | = Community =
| |
− |
| |
− | [https://www.iamthecavalry.org/ I Am The Cavalry]
| |
− |
| |
− | A global grassroots organization that is focused on issues where computer security intersects public safety and human life.
| |
− |
| |
− | Their areas of focus include:
| |
− | * Medical devices
| |
− | * Automobiles
| |
− | * Home Electronics
| |
− | * Public Infrastructure
| |
− |
| |
− | [https://otalliance.org Online Trust Alliance]
| |
− |
| |
− | Formed as an informal industry working group in 2005, today OTA is an Internal Revenue Service (IRS) approved 501c3 charitable organization with the mission to enhance online trust and empower users, while promoting innovation and the vitality of the internet. OTA is global organization supported by over 100 organizations headquartered in Bellevue, Washington with offices in Washington DC.
| |
− |
| |
− | Addressing the mounting concerns, in January 2015 the Online Trust Alliance, established the [https://otalliance.org/initiatives/internet-things IoT Trustworthy Working Group (ITWG)], a multi-stakeholder initiative. The group recognizes “security and privacy by design” must be a priority from the onset of product development and be addressed holistically. The framework focuses on privacy, security sustainability. The sustainability pillar is critical as it looks at the life-cycle issues related to long- term supportability and transfers of ownership of devices and the data collected.
| |
− |
| |
− | [https://allseenalliance.org/framework AllSeen Alliance]
| |
− |
| |
− | The AllSeen Alliance is a Linux Foundation collaborative project. They're a cross-industry consortium dedicated to enabling the interoperability of billions of devices, services and apps that comprise the Internet of Things. The Alliance supports the AllJoyn Framework, an open source software framework that makes it easy for devices and apps to discover and communicate with each other. Developers can write applications for interoperability regardless of transport layer, manufacturer, and without the need for Internet access. The software has been and will continue to be openly available for developers to download, and runs on popular platforms such as Linux and Linux-based Android, iOS, and Windows, including many other lightweight real-time operating systems.
| |
− |
| |
− | [http://www.iiconsortium.org/ The Industrial Internet Consortium (IIC)]
| |
− |
| |
− | The Industrial Internet Consortium is the open membership, international not-for-profit consortium that is setting the architectural framework and direction for the Industrial Internet. Founded by AT&T, Cisco, GE, IBM and Intel in March 2014, the consortium’s mission is to coordinate vast ecosystem initiatives to connect and integrate objects with people, processes and data using common architectures, interoperability and open standards.
| |
− |
| |
− | [http://securingsmartcities.org/ Securing Smart Cities]
| |
− |
| |
− | Securing Smart Cities is a not-for-profit global initiative that aims to solve the existing and future cybersecurity problems of smart cities through collaboration between companies, governments, media outlets, other not-for-profit initiatives and individuals across the world.
| |
− |
| |
− | ===Talks===
| |
− |
| |
− | RSA Conference San Francisco <br>
| |
− | [https://www.owasp.org/images/5/51/RSAC2015-OWASP-IoT-Miessler.pdf Securing the Internet of Things: Mapping IoT Attack Surface Areas with the OWASP IoT Top 10 Project] <br>
| |
− | Daniel Miessler, Practice Principal <br>
| |
− | April 21, 2015 <br>
| |
− | --- <br>
| |
− | Defcon 23 <br>
| |
− | [https://www.owasp.org/images/3/36/IoTTestingMethodology.pdf IoT Attack Surface Mapping] <br>
| |
− | Daniel Miessler <br>
| |
− | August 6-9, 2015
| |
− |
| |
− | ===Podcasts===
| |
− |
| |
− | * [http://iotpodcast.com/ The Internet of Things Podcast]
| |
− | * [http://www.iot-inc.com/ IoT Inc]
| |
− | * [https://craigsmith.net/iot-this-week/ IoT This Week]
| |
− | * [http://farstuff.com/ Farstuff: The Internet of Things Podcast]
| |
− |
| |
− | ===IoT Conferences===
| |
− |
| |
− | * [http://www.iotevents.org Internet of Things Events]
| |
− |
| |
− | Conference Call for Papers
| |
− | * [http://www.wikicfp.com/cfp/servlet/tool.search?q=internet+of+things&year=t WikiCFP - Internet of Things]
| |
− | * [http://www.wikicfp.com/cfp/servlet/tool.search?q=iot&year=t WikiCFP - IoT]
| |
− |
| |
− |
| |
| | | |
| =Project About= | | =Project About= |