<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>security and privacy. Journal of Advanced Research</journal-title>
      </journal-title-group>
      <issn pub-type="ppub">2090-1232</issn>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.1109/WOSQ.2009.5071558</article-id>
      <title-group>
        <article-title>An overview on the security technological levels in the Italian Smart Cities</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vita Santa Barletta</string-name>
          <email>vita.barletta@uniba.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Paolo Buono</string-name>
          <email>paolo.buono@uniba.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Danilo Caivano</string-name>
          <email>danilo.caivano@uniba.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Giovanni Dimauro</string-name>
          <email>giovanni.dimauro@uniba.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Antonio Pontrelli</string-name>
          <email>antonio.pontrelli@exprivia.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Computer Science, University of Bari Aldo Moro</institution>
          ,
          <addr-line>Via Orabona 4, 70125, Bari</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Exprivia S.p.a.</institution>
          ,
          <addr-line>Molfetta</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <volume>1010</volume>
      <issue>4</issue>
      <fpage>274</fpage>
      <lpage>279</lpage>
      <abstract>
        <p>A Smart City is a multidimensional entity based on Information and Communication Technologies (ICT) and intelligent (smart) use of urban infrastructures for improving the quality of life of its citizens. The management of such technologies and services for the citizens requires addressing adequately the security. The goal of this research work is to analyze existing potentially vulnerable devices in Smart Cities, in order to understand the security level of the city, and thus provide support for a secure management of the city. An analysis on 5 Italian Smart Cities was performed, each one was evaluated on different technological layers: Network and Infrastructure, Sensors, Service Delivery Platform, Application and Services. The results show that currently there are potentially vulnerable devices across different technological levels that compromise security and privacy of smart services offered to citizens. The development of a Smart City requires the implementation of security controls, in order to reduce the possibility for attackers to exploit existing vulnerabilities in the analyzed devices.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Security Smart City</kwd>
        <kwd>Security IoT</kwd>
        <kwd>Privacy by Design</kwd>
        <kwd>Secure Project Management</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        A Smart City integrates physical, digital and human systems to deliver a sustainable, prosperous and
inclusive future for its citizens [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. In order to improve economic and political efficiency and enable
social, cultural, and urban development, the smart city must include a networked infrastructure. Specific
goals are: the business development and social inclusion of urban residents in public services; high-tech
and creative industries in long-term urban growth; attention to social and relational capital in urban
development; social and environmental sustainability [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        The services of a smart city aim to improve the quality of life of the citizen in different domain
sectors. An example is related to digital accounts, that citizens use anywhere and anytime in services
that require the users’ identity. Any service that accesses and provides sensitive data may ask the
identity of the user to prevent data leaks or improper access to such data. Digital accounts are used to
access such services [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. A smart city has more services, since the intelligence of a city is implemented
through the deployment of devices, sensors, infrastructures that connect objects and people through
services in various areas. From a conceptual point of view, a Smart City can be organized on a
bidimensional model where one (horizontal) dimension represents the four overlapping technological
layers: network and infrastructure, sensors, service delivery platform, application and services; a second
(vertical) dimension includes the application domains: people, energy, economy, mobility, living,
environment, planning, government.
      </p>
      <p>
        The increase in connectivity in an enabling factor to be smarter, but this increases the possibilities
for cyber attacks and consequently the vulnerability. In order to reduce security threats and incidents,
the Smart City should identify threats timely, define and adjust strategies and activities [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. In order to
meet these needs this work analyzed 5 Italian Smart Cities, seeking for vulnerable devices that may
become access points for cyber-attacks on the city. An overview of the technological levels of the
security of Italian Smart Cities is the first step to plan correctly actions and implement infrastructures.
      </p>
      <p>The paper is organized as follows: Section 2 discusses related works; Section 3 briefly presents the
Smart City Integrated Model; Section 4 describes the performed analysis; Section 5 reports results of
the analysis; Section 6 performs a discussion about initial findings of this work; Section 7 highlights
limits and threats of the work; Section 8 concludes the paper.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related Works</title>
      <p>
        Smart city involves technological, economic and social improvement fueled by technologies based
on sensors, big data, open data, new connectivity ways and information exchange [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Therefore, smart
city security is essential to incorporate the technologies into smart city cyber infrastructure and to
improve the conditions of life for its citizens [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. For instance, in the mobility domain the diffusion of
embedded and portable communication devices on modern vehicles entails new security risks since
invehicle communication protocols are still insecure and vulnerable to attack [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>
        Integrity, authenticity, confidentiality and availability are important security requirements in the
different domains of the smart city to guarantee the availability of services and, consequently, the
connectivity of the city and the citizens [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. IoT plays a pivotal role within the infrastructure of smart
cities as it provides the network architecture responsible for gathering and processing data from
distributed sensors and smart devices [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. The data generated by unprotected smart city infrastructure
such as parking garages, or surveillance feeds provide cyber attackers with an ample amount of targeted
personal information that can potentially be exploited for fraudulent transactions and identity theft or
in some cases obtain control/access to such devices [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Therefore, the complexity of smart city [
        <xref ref-type="bibr" rid="ref12">12,13</xref>
        ]
impacts significantly on security (i.e., illegal access to information) and privacy within smart cities
seems to disappear considerably, digital citizens are more and more instrumented with data available
about their location and activities [14]. This requires the development of a comprehensive model of
security intelligent city management [15], just think of the residents of some buildings in the city of
Lappeenranta, who in November 2016 risked freezing to death inside their own homes at the hands of
a group of hackers who, by launching a DDoS attack on the central heating system, blocked its
operation, knocking out the boilers connected to the network.
      </p>
      <p>Smart Cities, if not properly designed and carefully administered [16], can become insecure
infrastructures, exposing public governance to the risk of cyberterrorism attacks [17]. Thus keeping in
mind the security and privacy challenges associated with the smart city, this research work aims to
report an overview of the security technological levels in Italian smart cities in order to provide the
necessary guidelines to be able to safely manage such cities and especially to be able to apply preventive
security measures.</p>
    </sec>
    <sec id="sec-3">
      <title>3. The Smart City Integrated Model</title>
      <p>
        A Smart City can monitor and integrate functionality of critical infrastructure like roads, tunnels,
airways, waterways, railways, communication power supply, etc., control maintenance activities and
can help in optimizing the resources while keeping an eye on the security issues as well [18]. Smart city
security has become one of the important issues in cyber security [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] and it is necessary to protect every
dimension on which a smart city develops its smart services [19].
      </p>
      <p>
        Generally, a conceptual approach to a smart city includes 6 dimensions [20]: people, government,
economy, mobility, environment and living that play a key role in the design of a smart city strategy
[21]. However, considering the concept of Smart Sustainable Cities [22] it is necessary to rethink how
to construct and manage cities with the help of technologies [23]. An analysis of different definitions
[24], models and approaches allow us to conceptually organize a smart city based on a two-dimensional
integrated model, as depicted in Fig. 1: horizontal dimension and vertical dimension [
        <xref ref-type="bibr" rid="ref3 ref4">3,4</xref>
        ].
      </p>
      <p>The Horizontal dimension represents a set of four overlapping technological layers: Network and
Infrastructure (telecommunication, mobility, energy and environment); Sensors, to collect big data from
connected objects in the city; Service Delivery Platform, to elaborate and enhance the big data generated
by the other layers; Application and Services which represents the interface with the end users. The
Vertical dimension includes the application domains in a Smart City: People, Energy, Economy,
Mobility, Living, Environment, Planning, Government.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Analysis of Smart Cities Security</title>
      <p>The research goal we address is to analyze existing potentially vulnerable devices in Smart Cities,
in order to understand the security level of the city, and thus provide support for a secure management
of the city. To this aim, we carried out an analysis on Internet-connected devices available in Shodan
[25], a search engine that scans the Internet IPs to look for available services. Such services are detected
by parsing banners, which are essentially text that allow for identifying login interfaces or certain
service characteristics [26]. Therefore, Shodan help to calculate if a target is legitimate or an actual
honeypot i.e., an application of deception technique, designed to gather information about the motives
and tactics of attackers [27]. It uses a machine learning algorithm that was ported to all of the crawlers
in the Shodan network.</p>
      <p>The Shodan crawlers continuously update the database in real-time, so that each query returns
upto-date information. The basic algorithm used by crawlers is [28]:
1. Generate a random IPv4 address
2. Generate a random port to test from the list of ports known by Shodan
3. Check the random IPv4 address on the random port and grab a banner
4. Goto 1</p>
      <p>Shodan has been used in different research works with the goal of identifying potentially vulnerable
IoT devices, an example is [29] whose authors selected a set of search terms to retrieve vulnerable IoT
devices with Shodan API and analyze the risk level. In [30], many SCADA devices and webcams were
identified using Shodan and with the aim of answering the following questions: “Can Shodan be used
for large scale vulnerability analysis on emerging threats? Can Real System exposure and vulnerabilities
be verified or quantified?”. Genge et al. expanded the features exposed by Shodan with advanced
vulnerability assessment capabilities embedded into a novel tool called Shodan-based vulnerability
assessment tool (ShoVAT) [31]. Taking into account the results obtained by such research works the
use of Shodan is identified as a good search engine for potentially insecure IoT devices within smart
cities.</p>
      <p>The research goal and questions have been defined according to the Goal-Question-Metrics
paradigm [32,33] as follows:</p>
      <p>Research Goal: Analyze Internet connected devices with the aim of characterizing them from a
cyber security point of view in the context of Smart City technological layers.</p>
      <p>Research Question (RQ): Which are the potentially vulnerable devices according to the horizontal
dimension of the model?</p>
      <p>Metric: Vulnerable devices (VD): Given a Horizontal Dimension i (HDi), VD(HDi) is equal to the
number of IP ports exposed to the Internet for that dimension.</p>
      <p>
        Selection of the experimental sample. In accordance with the previous research work that
investigated the need of Smart Program Management in the smart cities [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] the Italian scenario was
selected. In Figure 2 is reported the distribution of webcam in Italy. We selected the 5 cities having the
most of webcams for our analysis. These cities are Rome, Milan, Turin, Bari, Naples.
      </p>
      <p>Data Collection. Shodan collects data mostly on web servers (ports 80, 8080, 443, 8443), FTP (port
21), SSH (port 22), Telnet (port 23), SNMP (port 161), IMAP (ports 143, or 993), SMTP (port 25), SIP
(port 5060) and Real Time Streaming Protocol (RTSP, port 554). The data collected for each selected
device were: City, TCP Port, IoT protocol (e.g., webcam, FTP, industrial devices).</p>
      <p>Data Analysis. This step consisted in activities required to produce the analysis, such as data
cleaning, data formatting, charts creation.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Results</title>
      <p>As shown in Table 1, the experimental sample was composed of 5 smart cities and a total of 316.158
devices distributed in the Italian territory.</p>
      <p>As visible in Figure 3, Rome has the most IP cameras in the considered sample, most of them use
554 port. Even if Milan use half of the IP cameras compared to Rome, the number of IP cameras that
use the 37777 port is almost the same. Since the 554 port is considered less secure, we can infer that in
Milan more secure webcams are adopted.</p>
      <p>Figure 5 reports the use of IP ports for three different services that are used to connect remotely to
a device. The data are ordered by the total amount of such services. It is visible that in Milan, more than
other cities, such services are used. The analysis reveals that Milan contains the highest number of IP
ports in the different protocols. We can see that SSH protocol in Milan is much more used than FTP,
revealing more usage of SSH connections that typically are made using terminals. Moreover, in Rome,
the number of FTP is almost the same as SSH connections.</p>
      <p>Figure 6 reports the number of TCP ports used by industrial devices, ordered by TCP port and, for
each port all 5 cities of the sample are reported, ordered by the number of devices. Port 20000 contains
the highest number of devices, and then 102, 1911, and the others follows. It is very visible that Milan
has the highest number of TCP ports. This reveals a high traffic through industrial devices, which also
reveals the industrial soul of the city, that is projected to innovation and progress. Turin is the second
city in the use of industrial devices, which is not surprising, considering the industrial history of this
city. What is surprising is Rome, on the port 20000. Such ports are more used on SCADA systems,
which are intended for monitoring and controlling distributed industrial systems. It is reasonable to
think that being a bigger city than Turin, Rome has the highest number of such systems and thus uses
more devices that use 20000 TCP port.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Discussions</title>
      <p>We have collected data about existing IoT devices in Italy in January 2021 using the Shodan search
engine. We have defined a bi-dimensional model to perform our analysis, it considers a horizontal
dimension that is composed of four layers (see. Section 3); the vertical dimension considers 8 different
domains. We focused on the horizontal dimension that is composed of the layers: 1) Network and
Infrastructure; 2) Sensor; 3) Service Delivery Platform; 4) Application and Services. From the analysis
of such IoT devices, disaggregated by port, protocol and city we derived some assumption that we are
going to discuss here according to the research question reported in Section 4: Which are the potentially
vulnerable devices according to the horizontal dimension of the model?</p>
      <p>We observed that most of the devices focus on layer 1) and 4) that means most of the threats may
come from exploiting vulnerabilities on VoIP, FTP, SSH and RDP, TCP ports on IP Cameras (level 4)
and on industrial devices (level 1). While this may be obvious, it is interesting to analyze the different
distribution in different cities, according to the various services and devices.</p>
      <p>The cities with the highest number of IoT devices are Rome, Milan and Turin. The different
distribution of devices reveals the different city organization in terms of technological infrastructure
and services to the citizens.</p>
      <p>Regarding the level 1) of the model, Rome is the city with the highest number of IP webcams, which
reveals more control on security on the streets and public spaces. This is reasonable, if we consider that
Rome is a Capital and also a very touristic city. Rome has the highest number of devices that use VoIP
protocol, followed by Turin and then Milan, this is a bit surprising because Milan is a European city
very oriented to business, so it would have been reasonable to find Milan in the first place. In any case
this information has to be considered in the protection against cyber-attack.</p>
      <p>Regarding the level 4) of the model we see as Milan emerges with the very high presence of ports
used for remote connection, file exchange, and remote control in industrial contexts. Indeed, FTP, SSH
and RDP are mainly present in Milan, followed by Rome with around a half of the devices found in
Milan. This is in accordance with the TCP ports used in industrial contexts, such as SCADA systems
or PLC remote control of industrial settings (such as trains, airports). Milan in general is followed by
Turin in terms of number of devices that regard the layer 4), but there is an exception related to port
20000 which is used typically for distributed systems to monitor and control trains, buses, airports, and
the likes. Rome actually has more infrastructure than Turin, this means that Rome is more exposed than
Turin in terms of security in the layer 4).</p>
    </sec>
    <sec id="sec-7">
      <title>7. Limitations and Threats to Validity</title>
      <p>In order to provide the reader with all the elements for evaluating the presented results, possible
experimental threats to validity, consistency, magnitude of the results and transferability are analyzed
below. Threats to validity, internal validity, or credibility, is related to the extent that the results match
the meanings and knowledge constructed in the investigated context.</p>
      <p>To increase credibility in the study, we tried to achieve maximum variation collecting data from IoT
devices to different smart cities. We selected the top 5 Smart Cities that have the highest number of
webcams in the first round of analysis and then focused on the analysis across all the IoT devices
obtained for different cities. Consistency refers to whether the researchers did not make any inference
that cannot be supported by the data. To increase consistency, we performed all data analysis in groups.
The analysis was performed by one researcher and reviewed by all the other researchers. Member
checking was also used to check the consistency of our interpretations. Inconsistencies among
researchers were resolved in consensus meetings. We used the Framework Method to enhance the
consistency of data analysis among the researchers [34]. Finally, regarding the magnitude of the results,
in this work 316.158 IoT devices from 5 Italian smart cities were analyzed and this represents a limit
as the sample size is lower than the total number of Internet connected devices. Furthermore, the
selected devices are not worldwide and refer only to Italian Smart Cities.</p>
      <p>Therefore, we do not claim generalization of our results to a large population in a positivist
perspective. Instead, we believe that the analysis carried out by a search engine such as Shodan on
potentially vulnerable devices connected to the network is a good starting point to have a vision on the
Security Smart Cities. The use of a common search engine supported good analytical generalization
increasing the potential of transferability [35] of the findings to other contexts.</p>
    </sec>
    <sec id="sec-8">
      <title>8. Conclusions</title>
      <p>The research work presents an overview on the security technological levels in the Italian Smart
Cities. An analysis on Internet-connected devices available in Shodan was carried out in order to
achieve our goal, i.e., understand the security levels of the cities, and thus provide support for a
management that includes security. We analyzed 316.158 IoT devices from 5 Italian smart cities and
the results obtained show that the most vulnerable devices focus on Infrastructure and Network (layer
1) and Application and Services (Layer 4). This represents a first step of our research that aims to
investigate the impact of security in a complex context such as Smart Cities. We are planning to perform
a more extended analysis on all Italian cities.</p>
      <p>The results of the vulnerability study can be better presented by mapping services to specific risk
levels. This type of metric could be useful to derive a final vulnerability risk level of the smart city. The
presentation of the overview of the data can benefit from specific visualizations [36] that are capable to
show data in little space and give to the observer an immediate overview. This will lead also to another
positive outcome, if the visualization shows immediately the data, it can be used real-time to allow the
user to see data instantly. This will then lead to a successive step, that is to represent the evolution of
data over time.
9. References</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>British</surname>
            <given-names>Standards Institution.</given-names>
          </string-name>
          (
          <year>2014</year>
          ).
          <source>Smart Cities-Vocabulary. Last accessed on 12 February</source>
          <year>2021</year>
          , http://shop.bsigroup.com/ upload/PASs/Free-Download/PAS180.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>Trend</given-names>
            <surname>Micro</surname>
          </string-name>
          . (
          <year>2017</year>
          ).
          <article-title>Securing Smart Cities: Moving Toward Utopia with Security in Mind</article-title>
          .
          <source>Last accessed on 12 February</source>
          <year>2021</year>
          , https://documents.trendmicro.com/assets/wp/wp-securing-smartcities.pdf
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Baldassarre</surname>
            ,
            <given-names>M. T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Santa Barletta</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Caivano</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          (
          <year>2018</year>
          ).
          <article-title>Smart Program Management in a Smart City</article-title>
          . In 2018 AEIT International Annual Conference (pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          ). https://doi.org/10.23919/AEIT.
          <year>2018</year>
          .8577379
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Barletta</surname>
            ,
            <given-names>V.S.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Caivano</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ; Dimauro,
          <string-name>
            <given-names>G.</given-names>
            ;
            <surname>Nannavecchia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ;
            <surname>Scalera</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Managing</surname>
          </string-name>
          <article-title>a Smart City Integrated Model through Smart Program Management</article-title>
          .
          <source>Appl. Sci</source>
          .
          <year>2020</year>
          ,
          <volume>10</volume>
          , 714. https://doi.org/10.3390/app10020714
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Baldassarre</surname>
            ,
            <given-names>M.T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Barletta</surname>
            ,
            <given-names>V.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Caivano</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Raguseo</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Scalera</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <article-title>Teaching cyber security: The hack-space Integrated model (</article-title>
          <year>2019</year>
          ),
          <source>CEUR Workshop Proceedings</source>
          , 2315, ISSN:
          <fpage>16130073</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Gretzel</surname>
            ,
            <given-names>U.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Werthner</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Koo</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Lamsfus</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Conceptual foundations for understanding smart tourism ecosystems</article-title>
          .
          <source>Computers in Human Behavior</source>
          ,
          <volume>50</volume>
          ,
          <fpage>558</fpage>
          -
          <lpage>563</lpage>
          . https://doi.org/10.1016/j.chb.
          <year>2015</year>
          .
          <volume>03</volume>
          .043
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Ralko</surname>
          </string-name>
          , Shawn and Kumar,
          <source>Sathish, "Smart City Security"</source>
          (
          <year>2016</year>
          ).
          <source>KSU Proceedings on Cybersecurity Education, Research and Practice. 10. Last accessed on 12 February</source>
          <year>2021</year>
          , https://digitalcommons.kennesaw.edu/ccerp/2016/Academic/10
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Barletta</surname>
            ,
            <given-names>V.S.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Caivano</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Nannavecchia</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Scalera</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Intrusion Detection for in-Vehicle Communication Networks: An Unsupervised Kohonen SOM Approach</article-title>
          .
          <source>Future Internet</source>
          <year>2020</year>
          ,
          <volume>12</volume>
          , 119. https://doi.org/10.3390/fi12070119
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>ENISA.</surname>
          </string-name>
          (
          <year>2015</year>
          ).
          <article-title>Cyber security for Smart Cities</article-title>
          .
          <article-title>An architecture model for public transport</article-title>
          .
          <source>Last accessed on 12 February</source>
          <year>2021</year>
          ,
          <article-title>www</article-title>
          .enisa.europa.eu
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Ismagilova</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hughes</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rana</surname>
            ,
            <given-names>N.P.</given-names>
          </string-name>
          et al.
          <article-title>Security, Privacy and Risks Within Smart Cities: Literature Review and Development of a Smart City Interaction Framework</article-title>
          .
          <source>Inf Syst Front</source>
          (
          <year>2020</year>
          ). https://doi.org/10.1007/s10796-020-10044-1
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Rambus</surname>
          </string-name>
          . Smart Cities:
          <article-title>Threat and Countermeasures</article-title>
          .
          <source>Last accessed on 12 February</source>
          <year>2021</year>
          , https://www.rambus.com/iot/smart-cities/
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Baldassarre</surname>
            ,
            <given-names>M.T.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Barletta</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Caivano</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ; Scalera,
          <string-name>
            <surname>M.</surname>
          </string-name>
          <article-title>Integrating security and privacy in software development</article-title>
          .
          <source>Softw. Qual. J</source>
          .
          <year>2020</year>
          ,
          <fpage>1</fpage>
          -
          <lpage>32</lpage>
          . https://doi.org/10.1007/s11219-020-09501-6
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>