In recent years, The Internet of Things (IoT) is considered as one of the main technological revolutions, it connects heterogeneous devices, peoples, and services in order to exchange information and to improve existing deployments in different sectors. So far, existing security solutions are not adapted to this development, considering that IoT resources are exposed to different intrusions, which impact security management efficiency and the need for human interventions to increase. Although, it is too hard to depend on manual approaches that require the deep involvement of security managers to deliver the aimed security level. Therefore, a new solution is needed, that will facilitate the decision against detected intrusions and according to their magnitudes and their intentions to put the necessary reaction in the right place. In this context, this paper proposes a model which specify how the decision and correlation scenario will be carried out when a critical alert comes from the intrusion detector basing on security policy rules. This model simplifies and facilitates the decision and reaction against detected intrusions by enriching it with the rules defined in security policy to ensure the protection of IoT resources and help security administrators to make the right decisions in other tasks.
Read full abstract