A Methodological Approach for the Security Analysis of FIWARE Technology

Authors

  • Juan Pablo Perata Facultad de Ingeniería, Universidad de la República
  • Gustavo Betarte

DOI:

https://doi.org/10.19153/cleiej.27.4.2

Keywords:

FIWARE, security assessment, threat analysis

Abstract

This paper presents the results of a security assessment of FIWARE technology. We adopted an offensive perspective to identify vulnerabilities in deploying FIWARE components in specific architecture configurations. We identify security issues by experimenting in a locally controlled environment and propose a threat model following the OWASP methodology. We implemented attacks for three of the identified attack goals and validated our approach with an exploratory analysis of an actual working and productive FIWARE platform. This analysis helped us distinguish different types of attacks, and we ended up with recommendations for components, architecture, and access control.

Downloads

Published

2024-09-06