IoTBlockSIEM for information security incident management in the internet of things ecosystem

  • PDF / 2,060,200 Bytes
  • 15 Pages / 595.276 x 790.866 pts Page_size
  • 15 Downloads / 203 Views

DOWNLOAD

REPORT


(0123456789().,-volV)(0123456789(). ,- volV)

IoTBlockSIEM for information security incident management in the internet of things ecosystem Natalia Miloslavskaya1 • Alexander Tolstoy1 Received: 3 October 2019 / Revised: 24 February 2020 / Accepted: 10 April 2020  Springer Science+Business Media, LLC, part of Springer Nature 2020

Abstract The Internet unfolded enormous opportunities to the modern computing world where not only humans but also computers and machines, as well as any tiny sensing devices, can communicate and collaborate. The Internet of Things (IoT) is still a new concept in its early stages after 20 years of successful usage in various application domains. Nowadays, the ‘‘Internet of Things Ecosystem’’ term is being used more often that emphasizes its complex internal structure and functionality. Based on the available standards on the IoT’s generalized architecture and reference model, the IoT ecosystem is presented as a security object to be protected. Numerous security controls, collecting raw data for complex and multi-stage processing and further detection of events related to information security (IS), are located on its layers. The IS incident management process with different routine actions for the IoT ecosystems needs automation, for which Security Information and Event Management (SIEM) systems are the best applicable solutions. But modern challenges require modifying two previously known generations of these systems, especially for the IoT ecosystems. A new blockchain-based system called the IoTBlockSIEM is proposed to solve this problem. An example of constructing transactions in the IoTBlockSIEM for the case of its use in managing IS incidents in the IoT ecosystem is provided. Further research concludes the article. Keywords Internet of things  IoT ecosystem  Security information and event management  SIEM system  Blockchain technology  Information security incident management  Information security incident  Information security event  Transaction

1 Introduction The Internet unfolded enormous opportunities to the modern computing world where not only humans but also computers and machines, as well as any tiny sensing

This article is an extended version of our paper published in A. Rocha et al. (eds.), New Knowledge in Information Systems and Technologies, Advances in Intelligent Systems and Computting, vol. 931—the Proceedings of the 7th World Conference on Information Systems and Technologies (WorldCIST’19), entitled ‘‘New SIEM for the Internet of Things’’  Springer International Publishing AG 2019. & Natalia Miloslavskaya [email protected] Alexander Tolstoy [email protected] 1

National Research Nuclear University MEPhI (Moscow Engineering Physics Institute), 31 Kashirskoye shosse, Moscow, Russia 115409

devices, can communicate and collaborate. After the explosion of the wireless devices market and the consequent introduction of the Wireless Sensor Networks (WSN) and Radio Frequency Identification (RFID) technologies, the Internet of Things (IoT) term has been coi