Shielding IoT against cyber-attacks: An event-based approach using SIEM

Daniel Diaz-López, Maria Blanco Uribe, Claudia Santiago Cely, Andrés Vega Torres, Nicolás Moreno Guataquira, Stefany Morón Castro, Pantaleone Nespoli, Félix Gómez Mármol

Research output: Contribution to journalArticlepeer-review

15 Scopus citations

Abstract

Due to the growth of IoT (Internet of Tings) devices in diferent industries and markets in recent years and considering the currently insufcient protection for these devices, a security solution safeguarding IoT architectures are highly desirable. An interesting perspective for the development of security solutions is the use of an event management approach, knowing that an event may become an incident when an information asset is afected under certain circumstances. Te paper at hand proposes a security solution based on the management of security events within IoT scenarios in order to accurately identify suspicious activities. To this end, diferent vulnerabilities found in IoT devices are described, as well as unique features that make these devices an appealing target for attacks. Finally, three IoT attack scenarios are presented, describing exploited vulnerabilities, security events generated by the attack, and accurate responses that could be launched to help decreasing the impact of the attack on IoT devices. Our analysis demonstrates that the proposed approach is suitable for protecting the IoT ecosystem, giving an adequate protection level to the IoT devices.
Original languageEnglish
Article number 3029638
Pages (from-to)1-18
Number of pages18
JournalWireless Communications and Mobile Computing
Issue number 3029638
StatePublished - 2018
Externally publishedYes

Fingerprint Dive into the research topics of 'Shielding IoT against cyber-attacks: An event-based approach using SIEM'. Together they form a unique fingerprint.

Cite this