Shielding IoT against Cyber‐Attacks: An Event‐Based Approach Using SIEM

Защита Интернета вещей от кибератак: событийный подход с использованием SIEM
Daniel Díaz López, María Blanco Uribe, Claudia Santiago Cely, Andrés Vega Torres, Nicolás Moreno Guataquira, Suhayla Khalil Viana de Castro, Pantaleone Nespoli, Félix Gómez Mármol
2018-01-01

IoT securitycyber-attacksevent-based securityintrusion detectionsecurity information and event management (SIEM)
Due to the growth of IoT (Internet of Things) devices in different industries and markets in recent years and considering the currently insufficient protection for these devices, a security solution safeguarding IoT architectures are highly desirable. An interesting perspective for the development of security solutions is the use of an event management approach, knowing that an event may become an incident when an information asset is affected under certain circumstances. The paper at hand proposes a security solution based on the management of security events within IoT scenarios in order to accurately identify suspicious activities. To this end, different vulnerabilities found in IoT devices are described, as well as unique features that make these devices an appealing target for attacks. Finally, three IoT attack scenarios are presented, describing exploited vulnerabilities, security events generated by the attack, and accurate responses that could be launched to help decreasing the impact of the attack on IoT devices. Our analysis demonstrates that the proposed approach is suitable for protecting the IoT ecosystem, giving an adequate protection level to the IoT devices.
1
It characterizes vulnerabilities and device-specific features that make IoT systems attractive targets for cyber-attacks.
2
The analysis indicates that the proposed approach can provide an adequate protection level and reduce attack impact on IoT devices.
3
The paper proposes an event-based IoT security solution using SIEM to identify suspicious activities through security-event management.
4
Three IoT attack scenarios connect exploited vulnerabilities with generated security events and corresponding mitigation responses.

IoT devices and architectures under cyber-attack scenarios

Event-based security-event management for identifying suspicious activities and enabling responses to IoT attacks

Publication Details
Publication Date
2018-01-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Daniel Díaz López
María Blanco Uribe
Claudia Santiago Cely
Andrés Vega Torres
Nicolás Moreno Guataquira
Suhayla Khalil Viana de Castro
Pantaleone Nespoli
Félix Gómez Mármol
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%