Budi Rahardjo
Institut Teknologi Bandung

Published : 2 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 2 Documents
Search

Attack Scenarios and Security Analysis of MQTT Communication Protocol in IoT System Syaiful Andy; Budi Rahardjo; Bagus Hanindhito
Proceeding of the Electrical Engineering Computer Science and Informatics Vol 4: EECSI 2017
Publisher : IAES Indonesia Section

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (784.215 KB) | DOI: 10.11591/eecsi.v4.1064

Abstract

Various communication protocols are currently used in the Internet of Things (IoT) devices. One of the protocols that are already standardized by ISO is MQTT protocol (ISO / IEC 20922: 2016). Many IoT developers use this protocol because of its minimal bandwidth requirement and low memory consumption. Sometimes, IoT device sends confidential data that should only be accessed by authorized people or devices. Unfortunately, the MQTT protocol only provides authentication for the security mechanism which, by default, does not encrypt the data in transit thus data privacy, authentication, and data integrity become problems in MQTT implementation. This paper discusses several reasons on why there are many IoT system that does not implement adequate security mechanism. Next, it also demonstrates and analyzes how we can attack this protocol easily using several attack scenarios. Finally, after the vulnerabilities of this protocol have been examined, we can improve our security awareness especially in MQTT protocol and then implement security mechanism in our MQTT system to prevent such attack
Anomaly Detection and Data Recovery on Mini Batch Distillation Column based Cyber Physical System Wedar Panji Mardyaningsih; Pranoto Rusmin; Budi Rahardjo
Proceeding of the Electrical Engineering Computer Science and Informatics Vol 6: EECSI 2019
Publisher : IAES Indonesia Section

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.11591/eecsi.v6.1990

Abstract

The development of industrial revolution 4.0 in industrial sector opened a cyber gap for outsiders to pose a threat to the system. Industrial control systems initially designed to meet SRA (Safety, Reliability, and Availability) priorities are now beginning to be pressed to consider security aspects related to the magnitude of the impact that can be caused due to external attacks. In making a safe Cyber Physical System (CPS) based automation, risk assessment will be used to determine the level risk of threat. Mini distillation column batch based CPS will be implemented as the approach of CPS in industrial sector. Anomaly detection based data-driven model and data recovery method is proposed to lower the impact of attack on this system.