当前位置: X-MOL 学术Cluster Comput. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
IoTBlockSIEM for information security incident management in the internet of things ecosystem
Cluster Computing ( IF 4.4 ) Pub Date : 2020-06-29 , DOI: 10.1007/s10586-020-03110-5
Natalia Miloslavskaya , Alexander Tolstoy

The Internet unfolded enormous opportunities to the modern computing world where not only humans but also computers and machines, as well as any tiny sensing devices, can communicate and collaborate. The Internet of Things (IoT) is still a new concept in its early stages after 20 years of successful usage in various application domains. Nowadays, the "Internet of Things Ecosystem" term is being used more often that emphasizes its complex internal structure and functionality. Based on the available standards on the IoT’s generalized architecture and reference model, the IoT ecosystem is presented as a security object to be protected. Numerous security controls, collecting raw data for complex and multi-stage processing and further detection of events related to information security (IS), are located on its layers. The IS incident management process with different routine actions for the IoT ecosystems needs automation, for which Security Information and Event Management (SIEM) systems are the best applicable solutions. But modern challenges require modifying two previously known generations of these systems, especially for the IoT ecosystems. A new blockchain-based system called the IoTBlockSIEM is proposed to solve this problem. An example of constructing transactions in the IoTBlockSIEM for the case of its use in managing IS incidents in the IoT ecosystem is provided. Further research concludes the article.



中文翻译:

IoTBlockSIEM用于物联网生态系统中的信息安全事件管理

互联网为现代计算世界带来了巨大的机会,在现代计算世界中,不仅人类而且计算机和机器以及任何微小的传感设备都可以进行通信和协作。物联网(IoT)在各种应用领域中成功使用了20年后仍处于早期的新概念。如今,“物联网生态系统”一词被越来越多地使用,强调其复杂的内部结构和功能。根据有关物联网通用架构和参考模型的可用标准,物联网生态系统被介绍为要保护的安全对象。许多安全控件位于其层上,这些控件收集原始数据以进行复杂的多阶段处理,并进一步检测与信息安全(IS)相关的事件。对于物联网生态系统而言,具有不同常规动作的IS事件管理流程需要自动化,因此安全信息和事件管理(SIEM)系统是最适用的解决方案。但是现代挑战要求修改这些系统的两个先前已知的版本,尤其是对于物联网生态系统。为了解决这个问题,提出了一种新的基于区块链的系统IoTBlockSIEM。提供了一个在IoTBlockSIEM中构造事务的示例,用于在IoT生态系统中管理IS事件的情况。进一步的研究总结了这篇文章。但是现代挑战要求修改这些系统的两个先前已知的版本,尤其是对于物联网生态系统。为了解决这个问题,提出了一种新的基于区块链的系统,称为IoTBlockSIEM。提供了一个在IoTBlockSIEM中构造事务的示例,用于在IoT生态系统中管理IS事件的情况。进一步的研究总结了这篇文章。但是现代挑战要求修改这些系统的两个先前已知的版本,尤其是对于物联网生态系统。为了解决这个问题,提出了一种新的基于区块链的系统,称为IoTBlockSIEM。提供了一个在IoTBlockSIEM中构造事务的示例,用于在IoT生态系统中管理IS事件的情况。进一步的研究总结了这篇文章。

更新日期:2020-06-29
down
wechat
bug