A Methodological Approach for the Security Analysis of FIWARE Technology
DOI:
https://doi.org/10.19153/cleiej.27.4.2Keywords:
FIWARE, security assessment, threat analysisAbstract
This paper presents the results of a security assessment of FIWARE technology. We adopted an offensive perspective to identify vulnerabilities in deploying FIWARE components in specific architecture configurations. We identify security issues by experimenting in a locally controlled environment and propose a threat model following the OWASP methodology. We implemented attacks for three of the identified attack goals and validated our approach with an exploratory analysis of an actual working and productive FIWARE platform. This analysis helped us distinguish different types of attacks, and we ended up with recommendations for components, architecture, and access control.
Downloads
Published
Issue
Section
License
Copyright (c) 2024 Juan Pablo Perata, Gustavo Betarte

This work is licensed under a Creative Commons Attribution 4.0 International License.
CLEIej is supported by its home institution, CLEI, and by the contribution of the Latin American and international researchers community, and it does not apply any author charges whatsoever for submitting and publishing. Since its creation in 1998, all contents are made publicly accesibly. The current license being applied is a (CC)-BY license (effective October 2015; between 2011 and 2015 a (CC)-BY-NC license was used).