The wide variety of application domains makes the Internet of Things (IoT) quite unique among other types of computer networks: IoT networks can be made of devices of different types, i.e., characterized by different hardware, functionalities, computing capabilities, and also network topology and communication protocols may drastically change from one IoT application to another. Such a heterogeneity requires ad-hoc security solutions, as security techniques that are effective in one IoT context may not be so in another context. Furthermore, IoT networks are ever evolving by their very nature as smart devices can be easily added or removed. These factors call for the design of security tools capable of adapting themselves to the specific IoT instance, but also to the continuous network changes. In this article we propose a context-aware, Security-as-a-Service-based approach for intrusion detection whereby an IDS: 1) autonomously collects information about the monitored system; 2) chooses the best detection strategy accordingly; and 3) modifies the detection strategy as the network evolves over time. This comprehensive approach to intrusion detection is an attempt to face the heterogeneity which characterizes the IoT in all its aspects, making it possible the design of a security tool able to be self-adaptive and context-aware, that is, effective in different and evolving IoT scenarios with little or no human intervention.

Kalis2.0 - A SECaaS-Based Context-Aware Self-Adaptive Intrusion Detection System for IoT

Rullo A.
Primo
Conceptualization
;
2024

Abstract

The wide variety of application domains makes the Internet of Things (IoT) quite unique among other types of computer networks: IoT networks can be made of devices of different types, i.e., characterized by different hardware, functionalities, computing capabilities, and also network topology and communication protocols may drastically change from one IoT application to another. Such a heterogeneity requires ad-hoc security solutions, as security techniques that are effective in one IoT context may not be so in another context. Furthermore, IoT networks are ever evolving by their very nature as smart devices can be easily added or removed. These factors call for the design of security tools capable of adapting themselves to the specific IoT instance, but also to the continuous network changes. In this article we propose a context-aware, Security-as-a-Service-based approach for intrusion detection whereby an IDS: 1) autonomously collects information about the monitored system; 2) chooses the best detection strategy accordingly; and 3) modifies the detection strategy as the network evolves over time. This comprehensive approach to intrusion detection is an attempt to face the heterogeneity which characterizes the IoT in all its aspects, making it possible the design of a security tool able to be self-adaptive and context-aware, that is, effective in different and evolving IoT scenarios with little or no human intervention.
2024
Istituto di Calcolo e Reti ad Alte Prestazioni - ICAR
Context awareness
device features
Internet of Things (IoT)
intrusion detection system (IDS)
network features
security-as-a-service (SECaaS)
software architecture
File in questo prodotto:
File Dimensione Formato  
Kalis2.0A_SECaaS-Based_Context-Aware_Self-Adaptive_Intrusion_Detection_System_for_IoT.pdf

accesso aperto

Tipologia: Versione Editoriale (PDF)
Licenza: Creative commons
Dimensione 4.13 MB
Formato Adobe PDF
4.13 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/533712
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 1
  • ???jsp.display-item.citation.isi??? 1
social impact