{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:23:58Z","timestamp":1783009438448,"version":"3.54.5"},"reference-count":55,"publisher":"Wiley","issue":"1","license":[{"start":{"date-parts":[[2018,10,25]],"date-time":"2018-10-25T00:00:00Z","timestamp":1540425600000},"content-version":"vor","delay-in-days":297,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100000780","name":"European Commission","doi-asserted-by":"publisher","award":["H2020-ICT-2014-2\/671672-SELFNET"],"award-info":[{"award-number":["H2020-ICT-2014-2\/671672-SELFNET"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003329","name":"Ministerio de Econom\u00eda y Competitividad","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003329","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004895","name":"European Social Fund","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004895","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007406","name":"Fundaci\u00f3n BBVA","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100007406","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["Wireless Communications and Mobile Computing"],"published-print":{"date-parts":[[2018,1]]},"abstract":"<jats:p>Due to the growth of IoT (Internet of Things) devices in different industries and markets in recent years and considering the currently insufficient protection for these devices, a security solution safeguarding IoT architectures are highly desirable. An interesting perspective for the development of security solutions is the use of an event management approach, knowing that an event may become an incident when an information asset is affected under certain circumstances. The paper at hand proposes a security solution based on the management of security events within IoT scenarios in order to accurately identify suspicious activities. To this end, different vulnerabilities found in IoT devices are described, as well as unique features that make these devices an appealing target for attacks. Finally, three IoT attack scenarios are presented, describing exploited vulnerabilities, security events generated by the attack, and accurate responses that could be launched to help decreasing the impact of the attack on IoT devices. Our analysis demonstrates that the proposed approach is suitable for protecting the IoT ecosystem, giving an adequate protection level to the IoT devices.<\/jats:p>","DOI":"10.1155\/2018\/3029638","type":"journal-article","created":{"date-parts":[[2018,10,25]],"date-time":"2018-10-25T23:45:47Z","timestamp":1540511147000},"update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":41,"title":["Shielding IoT against Cyber\u2010Attacks: An Event\u2010Based Approach Using SIEM"],"prefix":"10.1155","volume":"2018","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7244-2631","authenticated-orcid":false,"given":"Daniel","family":"D\u00edaz L\u00f3pez","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mar\u00eda","family":"Blanco Uribe","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7174-5910","authenticated-orcid":false,"given":"Claudia","family":"Santiago Cely","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andr\u00e9s","family":"Vega Torres","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nicol\u00e1s","family":"Moreno Guataquira","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stefany","family":"Mor\u00f3n Castro","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pantaleone","family":"Nespoli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6424-3322","authenticated-orcid":false,"given":"F\u00e9lix","family":"G\u00f3mez M\u00e1rmol","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"311","published-online":{"date-parts":[[2018,10,25]]},"reference":[{"key":"e_1_2_11_1_2","doi-asserted-by":"publisher","DOI":"10.1155\/2017\/1350929"},{"key":"e_1_2_11_2_2","unstructured":"Gartner \u201cGartner\u2019s 2016 Hype Cycle for Emerging Technologies \u201d 2016. [Online]. Available:https:\/\/www.gartner.com\/newsroom\/id\/3412017."},{"key":"e_1_2_11_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-014-9492-7"},{"key":"e_1_2_11_4_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00985-3_2"},{"key":"e_1_2_11_5_2","doi-asserted-by":"publisher","DOI":"10.1155\/2017\/6560797"},{"key":"e_1_2_11_6_2","doi-asserted-by":"publisher","DOI":"10.1155\/2017\/8323646"},{"key":"e_1_2_11_7_2","doi-asserted-by":"crossref","unstructured":"GomesB. MunizL. da Silva e SilvaF. J. RiosL. E. andEndlerM. A comprehensive cloud-based IoT software infrastructure for Ambient Assisted Living Proceedings of the 2015 International Conference on Cloud Technologies and Applications (CloudTech) June 2015 Marrakech Morocco 1\u20138 https:\/\/doi.org\/10.1109\/CloudTech.2015.7336998.","DOI":"10.1109\/CloudTech.2015.7336998"},{"key":"e_1_2_11_8_2","doi-asserted-by":"crossref","unstructured":"CharmonmanS.andMongkhonvanitP. Special consideration for Big Data in IoE or Internet of Everything Proceedings of the 13th International Conference on ICT and Knowledge Engineering ICT and KE 2015 November 2015 Thailand 147\u2013150 2-s2.0-84960447920.","DOI":"10.1109\/ICTKE.2015.7368487"},{"key":"e_1_2_11_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/comst.2015.2388550"},{"key":"e_1_2_11_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2014.2306328"},{"key":"e_1_2_11_11_2","doi-asserted-by":"crossref","unstructured":"KhanR. KhanS. U. andZaheerR. Future internet: the internet of things architecture possible applications and key challenges Proceedings of the 10th International Conference on Frontiers of Information Technology (FIT\u2032 12) December 2012 257\u2013260 https:\/\/doi.org\/10.1109\/fit.2012.53 2-s2.0-84874174122.","DOI":"10.1109\/FIT.2012.53"},{"key":"e_1_2_11_12_2","doi-asserted-by":"publisher","DOI":"10.1155\/2017\/3859836"},{"key":"e_1_2_11_13_2","doi-asserted-by":"crossref","unstructured":"HwangY. H. IoT security & privacy: Threats and challenges Proceedings of the 1st ACM Workshop on IoT Privacy Trust and Security IoTPTS 2015 Singapore 2-s2.0-84955456292.","DOI":"10.1145\/2732209.2732216"},{"key":"e_1_2_11_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-41354-9_9"},{"key":"e_1_2_11_15_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2014.11.008"},{"key":"e_1_2_11_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2017.09.003"},{"key":"e_1_2_11_17_2","doi-asserted-by":"publisher","DOI":"10.3103\/S0146411616080125"},{"key":"e_1_2_11_18_2","doi-asserted-by":"crossref","unstructured":"ZegzhdaP. ZegzhdaD. KalininM. PechenkinA. MininA. andLavrovaD. Safe integration of SIEM systems with Internet of Things: Data aggregation integrity control and bioinspired safe routing Proceedings of the 9th International Conference on Security of Information and Networks SIN 2016 July 2016 USA 81\u201387 2-s2.0-84983414933.","DOI":"10.1145\/2947626.2947639"},{"key":"e_1_2_11_19_2","doi-asserted-by":"crossref","unstructured":"HoG. LeungD. MishraP. HosseiniA. SongD. andWagnerD. Smart locks: Lessons for securing commodity internet of things devices Proceedings of the 11th ACM Asia Conference on Computer and Communications Security ASIA CCS 2016 June 2016 Xi\u2032an China 461\u2013472 https:\/\/doi.org\/10.1145\/2897845.2897886 2-s2.0-84979650451.","DOI":"10.1145\/2897845.2897886"},{"key":"e_1_2_11_20_2","article-title":"Owasp cheat sheets","volume":"315","author":"Woschek M.","year":"2015","journal-title":"pp"},{"key":"e_1_2_11_21_2","unstructured":"ISO\/IEC \u201cISO\/IEC 27032:2012 - Information technology\u00e2\u20ac\u201dSecurity techniques\u00e2\u20ac\u201dGuidelines for cybersecurity \u201dhttps:\/\/www.iso.org\/standard\/44375.html 2012."},{"key":"e_1_2_11_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.201"},{"key":"e_1_2_11_23_2","doi-asserted-by":"crossref","unstructured":"SadeghiA.-R. WachsmannC. andWaidnerM. Security and privacy challenges in industrial internet of things Proceedings of the 52nd ACM\/EDAC\/IEEE Design Automation Conference (DAC \u203215) June 2015 San Francisco Calif USA IEEE 1\u20136 https:\/\/doi.org\/10.1145\/2744769.2747942.","DOI":"10.1145\/2744769.2747942"},{"key":"e_1_2_11_24_2","doi-asserted-by":"crossref","unstructured":"ProkofievA. O. SmirnovaY. S. andSurovV. A. A method to detect Internet of Things botnets Proceedings of the 2018 IEEE Conference of Russian Young Researchers in Electrical and Electronic Engineering (EIConRus) January 2018 Moscow 105\u2013108 https:\/\/doi.org\/10.1109\/EIConRus.2018.8317041.","DOI":"10.1109\/EIConRus.2018.8317041"},{"key":"e_1_2_11_25_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11235-017-0345-9"},{"key":"e_1_2_11_26_2","unstructured":"ISO\/IEC \u201cISO\/IEC 27000:2018 - Information technology-Security techniques-Information security management systems-Overview and vocabulary \u201dhttps:\/\/www.iso.org\/standard\/73906.html 2018."},{"key":"e_1_2_11_27_2","doi-asserted-by":"crossref","unstructured":"GuptaS. ChaudhariB. S. andChakrabartyB. Vulnerable network analysis using war driving and Security intelligence Proceedings of the 2016 International Conference on Inventive Computation Technologies ICICT 2016 August 2016 India 2-s2.0-85022320205.","DOI":"10.1109\/INVENTIVE.2016.7830165"},{"key":"e_1_2_11_28_2","volume-title":"Network and system security","author":"Vacca J. R","year":"2014"},{"key":"e_1_2_11_29_2","doi-asserted-by":"crossref","unstructured":"ChahidY. BenabdellahM. andAziziA. Internet of things security Proceedings of the 2017 International Conference on Wireless Technologies Embedded and Intelligent Systems WITS 2017 April 2017 Morocco 2-s2.0-85021686886.","DOI":"10.1109\/WITS.2017.7934655"},{"key":"e_1_2_11_30_2","unstructured":"R. Van Rijswijk and E. Poll \u201cUsing trusted execution environments in two\u2013factor authentication: comparing approaches \u201d ser. Lecture Notes in Informatics. 1em plus 0.5em minus 0.4em Bonn Germany: Gesellschaft for Informatik 9 2013 pp. 20\u201331."},{"key":"e_1_2_11_31_2","doi-asserted-by":"crossref","unstructured":"DoukasC. MaglogiannisI. KoufiV. MalamateniouF. andVassilacopoulosG. Enabling data protection through PKI encryption in IoT m-Health devices Proceedings of the 12th IEEE International Conference on BioInformatics and BioEngineering BIBE 2012 November 2012 25\u201329 2-s2.0-84872855613.","DOI":"10.1109\/BIBE.2012.6399701"},{"key":"e_1_2_11_32_2","first-page":"1","article-title":"Smart card-based secure authentication protocol in multi-server IoT environment","author":"Bae W.-I.","year":"2017","journal-title":"Multimedia Tools and Applications"},{"key":"e_1_2_11_33_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2017.02.009"},{"key":"e_1_2_11_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2018.3011034"},{"key":"e_1_2_11_35_2","unstructured":"I. Smith and D. Bailey \u201cIoT Security Guidelines for Endpoint Ecosystem \u201d GSM Association Tech. Rep. 2016. [Online]. Available:https:\/\/www.gsma.com\/iot\/wp-content\/uploads\/2016\/02\/CLP.13-v1.0.pdf."},{"key":"e_1_2_11_36_2","doi-asserted-by":"crossref","unstructured":"KasinathanP. CostamagnaG. KhaleelH. PastroneC. andSpiritoM. A. Demo: An ids framework for internet of things empowered by 6lowpan Proceedings of the 2013 ACM SIGSAC Conference on Computer; Communications Security 2013 1337\u20131340.","DOI":"10.1145\/2508859.2512494"},{"key":"e_1_2_11_37_2","unstructured":"NespoliP.andG\u00f3mez M\u00e1rmolF. e-Health Wireless IDS with SIEM integration IEEE Wireless Communications and Networking Conference (WCNC\u201918) 2018 Barcelona Spain."},{"key":"e_1_2_11_38_2","doi-asserted-by":"crossref","unstructured":"SforzinA. MarmolF. G. ContiM. andBohliJ. RPiDS: Raspberry Pi IDS \u2014 A Fruitful Intrusion Detection System for IoT Proceedings of the 2016 Intl IEEE Conferences on Ubiquitous Intelligence & Computing Advanced and Trusted Computing Scalable Computing and Communications Cloud and Big Data Computing Internet of People and Smart World Congress (UIC\/ATC\/ScalCom\/CBDCom\/IoP\/SmartWorld) July 2016 Toulouse France 440\u2013448 https:\/\/doi.org\/10.1109\/UIC-ATC-ScalCom-CBDCom-IoP-SmartWorld.2016.0080.","DOI":"10.1109\/UIC-ATC-ScalCom-CBDCom-IoP-SmartWorld.2016.0080"},{"key":"e_1_2_11_39_2","doi-asserted-by":"crossref","unstructured":"KotenkoI.andChechulinA. Computer attack modeling and security evaluation based on attack graphs Proceedings of the 2013 IEEE 7th International Conference on Intelligent Data Acquisition and Advanced Computing Systems IDAACS 2013 September 2013 Germany 614\u2013619 2-s2.0-84892661130.","DOI":"10.1109\/IDAACS.2013.6662998"},{"key":"e_1_2_11_40_2","doi-asserted-by":"crossref","unstructured":"KotenkoI.andChechulinA. Common Framework for Attack Modeling and Security Evaluation in SIEM Systems Proceedings of the 2012 IEEE International Conference on Green Computing and Communications (GreenCom) November 2012 Besancon France 94\u2013101 https:\/\/doi.org\/10.1109\/GreenCom.2012.24.","DOI":"10.1109\/GreenCom.2012.24"},{"key":"e_1_2_11_41_2","doi-asserted-by":"crossref","unstructured":"KambourakisG. KoliasC. andStavrouA. The Mirai botnet and the IoT Zombie Armies Proceedings of the 2017 IEEE Military Communications Conference MILCOM 2017 October 2017 USA 267\u2013272 2-s2.0-85042370568.","DOI":"10.1109\/MILCOM.2017.8170867"},{"key":"e_1_2_11_42_2","doi-asserted-by":"crossref","unstructured":"GeneiatakisD. KounelisI. NeisseR. Nai-FovinoI. SteriG. andBaldiniG. Security and privacy issues for an IoT based smart home Proceedings of the 40th International Convention on Information and Communication Technology Electronics and Microelectronics MIPRO 2017 May 2017 Croatia 1292\u20131297 2-s2.0-85027707774.","DOI":"10.23919\/MIPRO.2017.7973622"},{"key":"e_1_2_11_43_2","doi-asserted-by":"crossref","unstructured":"ZhangZ.-K. ChoM. C. Y. WangC.-W. HsuC.-W. ChenC.-K. andShiehS. IoT security: ongoing challenges and research opportunities Proceedings of the 7th IEEE International Conference on Service-Oriented Computing and Applications (SOCA \u203214) November 2014 Matsue Japan IEEE 230\u2013234 https:\/\/doi.org\/10.1109\/soca.2014.58 2-s2.0-84920514918.","DOI":"10.1109\/SOCA.2014.58"},{"key":"e_1_2_11_44_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.is.2014.07.006"},{"key":"e_1_2_11_45_2","unstructured":"G. Shpantzer \u201cImplementing hardware roots of trust: The trusted platform module comes of age \u201dSANS Whitepaper 2013. [Online]. Available:https:\/\/trustedcomputinggroup.org\/wp-content\/uploads\/SANS-Implementing-Hardware-Roots-of-Trust.pdf."},{"key":"e_1_2_11_46_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-03584-0_14"},{"key":"e_1_2_11_47_2","doi-asserted-by":"crossref","unstructured":"CichonskiP. MillarT. GranceT. andScarfoneK. Computer Security Incident Handling Guide : Recommendations of the National Institute of Standards and Technology National Institute of Standards and Technology 2012 no. NIST SP 800-61r2 https:\/\/doi.org\/10.6028\/NIST.SP.800-61r2.","DOI":"10.6028\/NIST.SP.800-61r2"},{"key":"e_1_2_11_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2014.10.012"},{"key":"e_1_2_11_49_2","article-title":"Optimal countermeasures selection against cyber attacks: A comprehensive survey on reaction frameworks","author":"Nespoli P.","year":"2017","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"e_1_2_11_50_2","volume-title":"ISSP guide to security essentials","author":"Gregory P. H.","year":"2014"},{"key":"e_1_2_11_51_2","unstructured":"Alienvault \u201cInsider\u2019s guide to Incident Response \u201dhttps:\/\/www.alienvault.com\/resource-center\/ebook\/insider-guide-to-incident-response-download 2017."},{"key":"e_1_2_11_52_2","volume-title":"CISSP: Certified Information Systems Security Professional Study Guide","author":"Tittle E.","year":"2012"},{"key":"e_1_2_11_53_2","doi-asserted-by":"crossref","unstructured":"PerumalS. Md NorwawiN. andRamanV. Internet of Things(IoT) digital forensic investigation model: Top-down forensic approach methodology Proceedings of the 5th International Conference on Digital Information Processing and Communications ICDIPC 2015 October 2015 Switzerland 19\u201323 2-s2.0-84962815572.","DOI":"10.1109\/ICDIPC.2015.7323000"},{"key":"e_1_2_11_54_2","unstructured":"RSA \u201cTwo-Factor Authentication Is a Must for Mobile \u201d 2016. [Online]. Available:https:\/\/www.rsa.com\/en-us\/blog\/2016-06\/two-factor-authentication-is-a-must-for-mobile."},{"key":"e_1_2_11_55_2","doi-asserted-by":"publisher","DOI":"10.1155\/2017\/7439361"}],"container-title":["Wireless Communications and Mobile Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/wcmc\/2018\/3029638.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/wcmc\/2018\/3029638.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1155\/2018\/3029638","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,7]],"date-time":"2024-08-07T07:13:16Z","timestamp":1723014796000},"score":1,"resource":{"primary":{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/10.1155\/2018\/3029638"}},"subtitle":[],"editor":[{"given":"Constantinos","family":"Kolias","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"editor"}]}],"short-title":[],"issued":{"date-parts":[[2018,1]]},"references-count":55,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,1]]}},"alternative-id":["10.1155\/2018\/3029638"],"URL":"https:\/\/doi.org\/10.1155\/2018\/3029638","archive":["Portico"],"relation":{},"ISSN":["1530-8669","1530-8677"],"issn-type":[{"value":"1530-8669","type":"print"},{"value":"1530-8677","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,1]]},"assertion":[{"value":"2018-05-28","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-10-04","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-10-25","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"3029638"}}