EN FR
EN FR


Section: New Software and Platforms

SCUBA

A Tool Suite for the automated security assessment of IoT environments

Keywords: Cybersecurity - Internet of things - Machine learning - Artificial intelligence

Functional Description: IoT devices are used in different fields of application, not only for the general public, but also in industrial environments. SCUBA is tool suite for the security assessment of industrial and general public IoT devices. It mainly relies on collected information through passive and active scanning of a running IoT device in its exploitation environment to build its Security Knowledge Base (SKB). The knowledge base contains all relevant information of the device regarding its network communications extracted from PCAP files, the enumeration of its used hardware and software represented in the CPE (Common Platform Enumeration) format, the list of its known vulnerabilities in the CVE (Common Vulnerabilities and Exposures) format associated to their CWE (Common Weakness Enumeration) and CAPEC (Common Attack Pattern Enumeration and Classification) descriptions. The SKB is used by SCUBA to predict the intrusion chains associated to an IoT device and its environment. SCUBA tries to be as automated as possible to face the large scale and the great heterogeneity of IoT networks.

News Of The Year: First release

  • Participants: Abdelkader Lahmadi, Frédéric Beck, Thomas Lacour and Jérôme François

  • Contact: Abdelkader Lahmadi