设计物联网实验室,提高学生对安全物联网系统的理解

A. Ravishankar Rao, Angela Elias-Medina
{"title":"设计物联网实验室,提高学生对安全物联网系统的理解","authors":"A. Ravishankar Rao,&nbsp;Angela Elias-Medina","doi":"10.1016/j.iotcps.2023.10.002","DOIUrl":null,"url":null,"abstract":"<div><p>In response to an alarming shortage of workers in cybersecurity and a growing skills gap, the U.S. Department of Defense is taking steps to build cybersecurity capacity through workforce training and education. In this paper, we present an approach to address this shortage and skills gap through the development of cybersecurity education courseware for internet of things (IoT) applications.</p><p>To attract students and workers into the field of cybersecurity, it is important to design courseware that is exciting and tied to real-world problems. We describe our design for an embedded systems course taught at the graduate level for engineering and computer science students. The innovation in our approach is to select the fast-growing domain of healthcare and feature different IoT sensors that are seeing increased usage. These include barcode scanners, cameras, fingerprint sensors, and pulse sensors. These devices cover important functions such as patient identification, monitoring, and creating electronic health records. We use a password protected MySQL database as a model for electronic health records. We also demonstrate potential vulnerabilities of these databases to SQL injection attacks.</p><p>We administered these labs and collected survey data from the students. We found a significant increase in student understanding of cybersecurity issues. The mean confidence level of the students in cybersecurity issues increased from 2.5 to 4.1 on a 5-point scale after taking this course, which represents a 65% increase. The instructional lab material has been uploaded to the web portal <span>https://clark.center</span><svg><path></path></svg> designated by the National Security Agency for dissemination. Our approach, design, and experimental validation methodology will be useful for educators, researchers, students, and organizations interested in re-skilling their workforce.</p></div>","PeriodicalId":100724,"journal":{"name":"Internet of Things and Cyber-Physical Systems","volume":"4 ","pages":"Pages 154-166"},"PeriodicalIF":0.0000,"publicationDate":"2023-11-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.sciencedirect.com/science/article/pii/S2667345223000536/pdfft?md5=cc95a3ddc1d4aa7611a556eb78ae2da5&pid=1-s2.0-S2667345223000536-main.pdf","citationCount":"0","resultStr":"{\"title\":\"Designing an internet of things laboratory to improve student understanding of secure IoT systems\",\"authors\":\"A. Ravishankar Rao,&nbsp;Angela Elias-Medina\",\"doi\":\"10.1016/j.iotcps.2023.10.002\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>In response to an alarming shortage of workers in cybersecurity and a growing skills gap, the U.S. Department of Defense is taking steps to build cybersecurity capacity through workforce training and education. In this paper, we present an approach to address this shortage and skills gap through the development of cybersecurity education courseware for internet of things (IoT) applications.</p><p>To attract students and workers into the field of cybersecurity, it is important to design courseware that is exciting and tied to real-world problems. We describe our design for an embedded systems course taught at the graduate level for engineering and computer science students. The innovation in our approach is to select the fast-growing domain of healthcare and feature different IoT sensors that are seeing increased usage. These include barcode scanners, cameras, fingerprint sensors, and pulse sensors. These devices cover important functions such as patient identification, monitoring, and creating electronic health records. We use a password protected MySQL database as a model for electronic health records. We also demonstrate potential vulnerabilities of these databases to SQL injection attacks.</p><p>We administered these labs and collected survey data from the students. We found a significant increase in student understanding of cybersecurity issues. The mean confidence level of the students in cybersecurity issues increased from 2.5 to 4.1 on a 5-point scale after taking this course, which represents a 65% increase. The instructional lab material has been uploaded to the web portal <span>https://clark.center</span><svg><path></path></svg> designated by the National Security Agency for dissemination. Our approach, design, and experimental validation methodology will be useful for educators, researchers, students, and organizations interested in re-skilling their workforce.</p></div>\",\"PeriodicalId\":100724,\"journal\":{\"name\":\"Internet of Things and Cyber-Physical Systems\",\"volume\":\"4 \",\"pages\":\"Pages 154-166\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-11-25\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://www.sciencedirect.com/science/article/pii/S2667345223000536/pdfft?md5=cc95a3ddc1d4aa7611a556eb78ae2da5&pid=1-s2.0-S2667345223000536-main.pdf\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Internet of Things and Cyber-Physical Systems\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2667345223000536\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Internet of Things and Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2667345223000536","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

为了应对网络安全工作者的惊人短缺和日益扩大的技能差距,美国国防部正在采取措施,通过劳动力培训和教育来建设网络安全能力。在本文中,我们提出了一种通过开发物联网(IoT)应用的网络安全教育课件来解决这一短缺和技能差距的方法。为了吸引学生和工作人员进入网络安全领域,重要的是要设计出令人兴奋的、与现实世界问题相关的课件。我们为工程和计算机科学专业的研究生开设的嵌入式系统课程描述了我们的设计。我们方法的创新之处在于选择快速增长的医疗保健领域,并采用使用量不断增加的不同物联网传感器。这些包括条形码扫描仪、摄像头、指纹传感器和脉冲传感器。这些设备涵盖了诸如患者识别、监控和创建电子健康记录等重要功能。我们使用密码保护的MySQL数据库作为电子健康记录的模型。我们还演示了这些数据库对SQL注入攻击的潜在漏洞。我们管理这些实验室并收集学生的调查数据。我们发现学生对网络安全问题的理解显著增加。学生对网络安全问题的平均信心水平(满分为5分)从2.5提高到4.1,提高了65%。教学实验材料已上传到国家安全局指定的门户网站https://clark.center上进行传播。我们的方法、设计和实验验证方法将对教育工作者、研究人员、学生和对劳动力再培训感兴趣的组织有用。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Designing an internet of things laboratory to improve student understanding of secure IoT systems

In response to an alarming shortage of workers in cybersecurity and a growing skills gap, the U.S. Department of Defense is taking steps to build cybersecurity capacity through workforce training and education. In this paper, we present an approach to address this shortage and skills gap through the development of cybersecurity education courseware for internet of things (IoT) applications.

To attract students and workers into the field of cybersecurity, it is important to design courseware that is exciting and tied to real-world problems. We describe our design for an embedded systems course taught at the graduate level for engineering and computer science students. The innovation in our approach is to select the fast-growing domain of healthcare and feature different IoT sensors that are seeing increased usage. These include barcode scanners, cameras, fingerprint sensors, and pulse sensors. These devices cover important functions such as patient identification, monitoring, and creating electronic health records. We use a password protected MySQL database as a model for electronic health records. We also demonstrate potential vulnerabilities of these databases to SQL injection attacks.

We administered these labs and collected survey data from the students. We found a significant increase in student understanding of cybersecurity issues. The mean confidence level of the students in cybersecurity issues increased from 2.5 to 4.1 on a 5-point scale after taking this course, which represents a 65% increase. The instructional lab material has been uploaded to the web portal https://clark.center designated by the National Security Agency for dissemination. Our approach, design, and experimental validation methodology will be useful for educators, researchers, students, and organizations interested in re-skilling their workforce.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
13.80
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信