Analyzing and Mitigating Attacks in IoT Smart Home Using a Threat Modeling Approach-Based STRIDE

Authors

DOI:

https://doi.org/10.3991/ijim.v19i02.52377

Keywords:

IoT, Device, IoT Smart Home, Threat Modeling, STRIDE, Attacks

Abstract


The Internet of Things (IoT) is a network of interconnected devices that enables data exchange. It is widely used in areas such as healthcare, aviation, agriculture, energy, and home automation. Despite its rapid growth and the massive adoption of connected devices, IoT presents significant security risks. Traditional threat modeling approaches are insufficient to address these risks. Architecture-based modeling is recommended, as it considers the entire system and helps in understanding potential threats. Threat modeling is a systematic technique used to identify and evaluate potential threats that could compromise the security of a system. The main objective is to understand the vulnerabilities of a system in order to design appropriate security measures to mitigate them. This paper aims to analyze and mitigate specific IoT smart home threats using the STRIDE threat modeling framework, which systematically identifies potential vulnerabilities at the development level. By applying STRIDE, which stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege, we focused on addressing key security threats, including denial of service (DoS), phishing, and man-in-the-middle (MitM) attacks. Our findings demonstrate that the proposed mitigation strategies are effective in countering these threats, providing a robust security layer for IoT smart homes. Through this study, we highlight the importance of architecture-based threat modeling to enhance security within the IoT ecosystem and offer practical solutions that strengthen IoT smart home resilience. The outcomes of the STRIDE-based analysis and the effectiveness of the mitigation techniques are detailed, offering empirical evidence to support our approach.

Author Biographies

Mariya Ouaissa, Cadi Ayyad University, Marrakech, Morocco

Mariya Ouaissa is a Professor in Cybersecurity and Networks at FSSM, Cadi Ayyad University, Marrakech, Morocco. She is a Ph.D. graduated in 2019 in Computer Science and Network from ENSAM, Moulay Ismail University, Meknes, Morocco. Her main research topics are Cybersecurity, IoT, M2M, D2D, WSN, Cellular Networks, Vehicular Networks. She has published over than 70 papers (Book Chapters, International Journals, and Conferences/Workshops), 20 Edited Books, and 10 Special Issues as guest editor.

Mariyam Ouaissa, Chouaib Doukkali University, El Jadida, Morocco

Mariyam Ouaissa is currently an Asssitant Professor in Netwroks and Systems at ENSA, Chouaib Doukkali University El Jadida, Morocco. She is a Ph.D. in Computer Science and Networks graduated in 2019 from Moulay Ismail University, ENSAM, Meknes, Morocco. Her main research topics are IoT, M2M, WSN, Vehicular Networks, Cellular Networks. She is mainly working on M2M congestion overload problem, security and the resource allocation management. She has published more than 50 research papers. She is Editor in several books (Springer, De Gruyter, RGN Publications ...) and Guest Editor in several special issues of journals.

Downloads

Published

2025-01-27

How to Cite

Ouaissa, M., & Ouaissa, M. (2025). Analyzing and Mitigating Attacks in IoT Smart Home Using a Threat Modeling Approach-Based STRIDE. International Journal of Interactive Mobile Technologies (iJIM), 19(02), pp. 126–142. https://doi.org/10.3991/ijim.v19i02.52377

Issue

Section

Papers