Netinfo Security ›› 2024, Vol. 24 ›› Issue (10): 1595-1603.doi: 10.3969/j.issn.1671-1122.2024.10.014

Previous Articles     Next Articles

Systematic Risk Assessment Analysis for Smart Wearable Devices

ZHAO Ge1,2(), ZHENG Yang3, TAO Zelin3,4   

  1. 1. The Third Research Institute of the Ministry of Public Security, Shanghai 200031, China
    2. Shanghai Engineering Research Center of Cyber and Information Security Evaluation, Shanghai 200031, China
    3. Wuxi Trusted Computing Technology Research Institute Co., Ltd., Wuxi 214187, China
    4. Faculty of Information Technology, Beijing University of Technology, Beijing 100124, China
  • Received:2024-06-01 Online:2024-10-10 Published:2024-09-27

Abstract:

Existing smart wearable devices generally have more vulnerable points and need to scientifically determine the risks they face through risk assessment. The current security risk assessment methods for smart wearable devices are mostly based on fragmented vulnerability points, without fully considering the systematic characteristics of the application scenarios of wearable devices, and are unable to assess the security risks as a whole. Therefore, the article proposed a risk assessment method for wearable devices based on a layered attack path diagram, which categorized the vulnerabilities of wearable devices according to their vulnerabilities’ location in the system, drew a multi-layer vulnerability relationship diagram, added direct threats and data asset targets facing the system to the diagram, and merged and calculated the attack paths from the direct threats, external vulnerability layer, indirect threats, to internal vulnerability layer attack target attack path for risk assessment. The proposed method takes the characteristics of system architecture into full consideration in the risk assessment process, which makes it easier and more accurate to assess the risk, and helps to find the bottlenecks of system security and evaluate the effectiveness of countermeasures.

Key words: risk assessment analysis, vulnerable point, smart wearables

CLC Number: