{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T13:51:14Z","timestamp":1762005074956,"version":"build-2065373602"},"reference-count":65,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2019,3,27]],"date-time":"2019-03-27T00:00:00Z","timestamp":1553644800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100007406","name":"Fundaci\u00f3n BBVA","doi-asserted-by":"publisher","award":["Leonardo Grant 2017"],"award-info":[{"award-number":["Leonardo Grant 2017"]}],"id":[{"id":"10.13039\/100007406","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Ram\u00f3n y Cajal research contract","award":["RYC-2015-18210"],"award-info":[{"award-number":["RYC-2015-18210"]}]},{"DOI":"10.13039\/501100010790","name":"Erasmus+","doi-asserted-by":"publisher","award":["2018-3538\/001-001"],"award-info":[{"award-number":["2018-3538\/001-001"]}],"id":[{"id":"10.13039\/501100010790","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The Internet of Things (IoT) became established during the last decade as an emerging technology with considerable potentialities and applicability. Its paradigm of everything connected together penetrated the real world, with smart devices located in several daily appliances. Such intelligent objects are able to communicate autonomously through already existing network infrastructures, thus generating a more concrete integration between real world and computer-based systems. On the downside, the great benefit carried by the IoT paradigm in our life brings simultaneously severe security issues, since the information exchanged among the objects frequently remains unprotected from malicious attackers. The paper at hand proposes COSMOS (Collaborative, Seamless and Adaptive Sentinel for the Internet of Things), a novel sentinel to protect smart environments from cyber threats. Our sentinel shields the IoT devices using multiple defensive rings, resulting in a more accurate and robust protection. Additionally, we discuss the current deployment of the sentinel on a commodity device (i.e., Raspberry Pi). Exhaustive experiments are conducted on the sentinel, demonstrating that it performs meticulously even in heavily stressing conditions. Each defensive layer is tested, reaching a remarkable performance, thus proving the applicability of COSMOS in a distributed and dynamic scenario such as IoT. With the aim of easing the enjoyment of the proposed sentinel, we further developed a friendly and ease-to-use COSMOS App, so that end-users can manage sentinel(s) directly using their own devices (e.g., smartphone).<\/jats:p>","DOI":"10.3390\/s19071492","type":"journal-article","created":{"date-parts":[[2019,3,29]],"date-time":"2019-03-29T03:38:52Z","timestamp":1553830732000},"page":"1492","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["COSMOS: Collaborative, Seamless and Adaptive Sentinel for the Internet of Things"],"prefix":"10.3390","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4041-1205","authenticated-orcid":false,"given":"Pantaleone","family":"Nespoli","sequence":"first","affiliation":[{"name":"Department of Information &amp; Communication Engineering, University of Murcia, Calle Campus Universitario, 30100 Murcia, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Useche Pelaez","sequence":"additional","affiliation":[{"name":"Department of System Engineering, Colombian School of Engineering Julio Garavito, AK 45 (Autonorte), Bogot\u00e1 205-59, Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7244-2631","authenticated-orcid":false,"given":"Daniel","family":"D\u00edaz L\u00f3pez","sequence":"additional","affiliation":[{"name":"Department of System Engineering, Colombian School of Engineering Julio Garavito, AK 45 (Autonorte), Bogot\u00e1 205-59, Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6424-3322","authenticated-orcid":false,"given":"F\u00e9lix","family":"G\u00f3mez M\u00e1rmol","sequence":"additional","affiliation":[{"name":"Department of Information &amp; Communication Engineering, University of Murcia, Calle Campus Universitario, 30100 Murcia, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2019,3,27]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Wang, T., Zhang, G., Liu, A., Bhuiyan, M.Z.A., and Jin, Q. (2018). A Secure IoT Service Architecture with an Efficient Balance Dynamics Based on Cloud and Edge Computing. IEEE Internet Things J.","DOI":"10.1109\/JIOT.2018.2870288"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"6900","DOI":"10.1109\/ACCESS.2017.2778504","article-title":"A Survey on the Edge Computing for the Internet of Things","volume":"6","author":"Yu","year":"2018","journal-title":"IEEE Access"},{"key":"ref_3","unstructured":"Nespoli, P., and G\u00f3mez M\u00e1rmol, F. (2018, January 15\u201318). e-Health Wireless IDS with SIEM integration. Proceedings of the IEEE Wireless Communications and Networking Conference (WCNC18), Barcelona, Spain."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"D\u00edaz L\u00f3pez, D., Blanco Uribe, M., Santiago Cely, C., Tarquino Murgueitio, D., Garcia Garcia, E., Nespoli, P., and G\u00f3mez M\u00e1rmol, F. (2018). Developing Secure IoT Services: A Security-Oriented Review of IoT Platforms. Symmetry, 10.","DOI":"10.3390\/sym10120669"},{"key":"ref_5","unstructured":"Gartner (2018, August 11). Gartner\u2019s 2016 Hype Cycle for Emerging Technologies Identifies Three Key Trends That Organizations Must Track to Gain Competitive Advantage. Available online: https:\/\/www.gartner.com\/newsroom\/id\/3412017."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Charmonman, S., and Mongkhonvanit, P. (2015, January 18\u201320). Special consideration for Big Data in IoE or Internet of Everything. Proceedings of the 13th International Conference on ICT and Knowledge Engineering (ICT Knowledge Engineering 2015), Bangkok, Thailand.","DOI":"10.1109\/ICTKE.2015.7368487"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"544","DOI":"10.1016\/j.future.2017.07.060","article-title":"Internet of Things security and forensics: Challenges and opportunities","volume":"78","author":"Conti","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1007\/s11277-017-4434-6","article-title":"Cyber Security Threats to IoT Applications and Service Domains","volume":"95","author":"Skouby","year":"2017","journal-title":"Wirel. Person. Commun."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1899","DOI":"10.1109\/JIOT.2017.2707465","article-title":"Security Vulnerabilities of Internet of Things: A Case Study of the Smart Plug System","volume":"4","author":"Ling","year":"2017","journal-title":"IEEE Internet Things J."},{"key":"ref_10","unstructured":"Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Durumeric, Z., Halderman, J.A., Invernizzi, L., and Kallitsis, M. (2017, January 16\u201318). Understanding the Mirai Botnet. Proceedings of the 26th USENIX Conference on Security Symposium (SEC17), Vancouver, BC, Canada."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Hwang, Y.H. (2015, January 14). IoT Security & Privacy: Threats and Challenges. Proceedings of the 1st ACM Workshop on IoT Privacy, Trust, and Security (IoTPTS15), Singapore.","DOI":"10.1145\/2732209.2732216"},{"key":"ref_12","first-page":"3029638","article-title":"Shielding IoT against cyber-attacks: An event-based approach using SIEM","volume":"2018","author":"Nespoli","year":"2018","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Nespoli, P., Zago, M., Huertas Celdr\u00e1n, A., Gil P\u00e9rez, M., G\u00f3mez M\u00e1rmol, F., and Garc\u00eda Clemente, F.J. (2018, January 15\u201318). A Dynamic Continuous Authentication Framework in IoT-Enabled Environments. Proceedings of the Fifth International Conference on Internet of Things: Systems, Management and Security (IoTSMS 2018), Valencia, Spain.","DOI":"10.1109\/IoTSMS.2018.8554389"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Lin, H., and Bergmann, N.W. (2016). IoT Privacy and Security Challenges for Smart Home Environments. Information, 7.","DOI":"10.3390\/info7030044"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Kambourakis, G., Gomez Marmol, F., and Wang, G. (2018). Security and Privacy in Wireless and Mobile Networks. Future Internet, 10.","DOI":"10.3390\/fi10020018"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Miettinen, M., Marchal, S., Hafeez, I., Asokan, N., Sadeghi, A.R., and Tarkoma, S. (2017, January 5\u20138). IoT SENTINEL: Automated Device-Type Identification for Security Enforcement in IoT. Proceedings of the IEEE 37th International Conference on Distributed Computing Systems (ICDCS17), Atlanta, GA, USA.","DOI":"10.1109\/ICDCS.2017.283"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1109\/MC.2013.74","article-title":"Cyberentity Security in the Internet of Things","volume":"46","author":"Ning","year":"2013","journal-title":"Computer"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Sforzin, A., G\u00f3mez M\u00e1rmol, F., Conti, M., and Bohli, J.M. (2016, January 18\u201321). RPiDS: Raspberry Pi IDS A Fruitful Intrusion Detection System for IoT. Proceedings of the IEEE Conference on Advanced and Trusted Computing, Toulouse, France.","DOI":"10.1109\/UIC-ATC-ScalCom-CBDCom-IoP-SmartWorld.2016.0080"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2716260","article-title":"Taxonomy and Survey of Collaborative Intrusion Detection","volume":"47","author":"Vasilomanolakis","year":"2015","journal-title":"ACM Comput. Surv."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Useche Pel\u00e1ez, D., D\u00edaz L\u00f3pez, D., Nespoli, P., and G\u00f3mez M\u00e1rmol, F. (2018, January 15\u201318). TRIS: A Three-Rings IoT Sentinel to protect against cyber-threats. Proceedings of the Fifth International Conference on Internet of Things: Systems, Management and Security (IoTSMS 2018), Valencia, Spain.","DOI":"10.1109\/IoTSMS.2018.8554432"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"1361","DOI":"10.1109\/COMST.2017.2781126","article-title":"Optimal Countermeasures Selection Against Cyber Attacks: A Comprehensive Survey on Reaction Frameworks","volume":"20","author":"Nespoli","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"13546","DOI":"10.1109\/ACCESS.2019.2893871","article-title":"Introducing Deep Learning Self-Adaptive Misuse Network Intrusion Detection Systems","volume":"7","author":"Papamartzivanos","year":"2019","journal-title":"IEEE Access"},{"key":"ref_23","unstructured":"Snort (2019, March 26). Network Intrusion Detection and Prevention System. Available online: https:\/\/www.snort.org\/."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Pathan, A.S.K. (2014). The State of the Art in Intrusion Prevention and Detection, Taylor & Francis.","DOI":"10.1201\/b16390"},{"key":"ref_25","unstructured":"Kismet (2019, March 26). Wireless Sniffer and Network Intrusion Detection System. Available online: https:\/\/www.kismetwireless.net."},{"key":"ref_26","unstructured":"OpenVAS (2019, March 26). Open Vulnerability Assessment System. Available online: http:\/\/www.openvas.org."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Varsalone, J., and McFadden, M. (2011). Defense against the Black Arts: How Hackers Do What They Do and How to Protect against It, Taylor & Francis.","DOI":"10.1201\/b11193"},{"key":"ref_28","unstructured":"YARA (2019, March 26). The Pattern Matching Swiss Knife for Malware Researchers. Available online: http:\/\/yara.readthedocs.io."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Latifi, S. (2016). Information Technology: New Generations: 13th International Conference on Information Technology, Springer International Publishing. Advances in Intelligent Systems and Computing.","DOI":"10.1007\/978-3-319-32467-8"},{"key":"ref_30","unstructured":"Weka (2019, March 26). Data Mining with Open Source Machine Learning Software. Available online: https:\/\/cs.waikato.ac.nz\/ml\/weka."},{"key":"ref_31","unstructured":"Kalu\u017ea, B. (2013). Instant Weka How-to, Packt Publishing."},{"key":"ref_32","unstructured":"Koodous (2019, March 26). Collaborative Platform for Android Malware Research. Available online: https:\/\/koodous.com."},{"key":"ref_33","unstructured":"APKMirror (2019, March 26). Free APK Downloads. Available online: https:\/\/www.apkmirror.com\/."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Arp, D., Spreitzenbarth, M., Huebner, M., Gascon, H., and Rieck, K. (2014, January 23\u201326). Drebin: Effective and Explainable Detection of Android Malware in Your Pocket. Proceedings of the 21th Annual Network and Distributed System Security Symposium (NDSS14), San Diego, CA, USA.","DOI":"10.14722\/ndss.2014.23247"},{"key":"ref_35","unstructured":"VirusTotal (2019, March 26). Free On-Line File Analyzer. Available online: https:\/\/www.virustotal.com."},{"key":"ref_36","unstructured":"Ciampa, M. (2017). CompTIA Security+ Guide to Network Security Fundamentals, Cengage Learning."},{"key":"ref_37","unstructured":"Radare (2019, March 26). Portable Reversing Framework. Available online: https:\/\/rada.re\/r."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Dunham, K., Hartman, S., Quintans, M., Morales, J.A., and Strazzere, T. (2014). Android Malware and Analysis, CRC Press. Information Security Books.","DOI":"10.1201\/b17598"},{"key":"ref_39","unstructured":"Drake, J.J., Lanier, Z., Mulliner, C., Fora, P.O., Ridley, S.A., and Wicherski, G. (2014). Android Hacker\u2019s Handbook, Wiley. EBL-Schweitzer."},{"key":"ref_40","unstructured":"OSSIM (2019, March 26). Alienvault Open-Source SIEM. Available online: https:\/\/www.alienvault.com\/products\/ossim."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Savas, O., and Deng, J. (2017). Big Data Analytics in Cybersecurity, CRC Press. Data Analytics Applications.","DOI":"10.1201\/9781315154374"},{"key":"ref_42","unstructured":"Akula, M., and Mahajan, A. (2017). Security Automation with Ansible 2: Leverage Ansible 2 to Automate Complex Security Tasks Like Application Security, Network Security, and Malware Analysis, Packt Publishing."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Dash, S.K., Suarez-Tangil, G., Khan, S., Tam, K., Ahmadi, M., Kinder, J., and Cavallaro, L. (2016, January 22\u201326). DroidScribe: Classifying Android Malware Based on Runtime Behavior. Proceedings of the IEEE Security and Privacy Workshops (SPW16), San Jose, CA, USA.","DOI":"10.1109\/SPW.2016.25"},{"key":"ref_44","unstructured":"Nespoli, P. (2017). WISS: Wireless IDS for IoT with SIEM integration. [Master\u2019s Thesis, University of Naples Federico II]."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Heriyanto, T., Allen, L., and Ali, S. (2014). Kali Linux: Assuring Security by Penetration Testing, Packt Publishing.","DOI":"10.1016\/S1353-4858(14)70077-7"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"333","DOI":"10.1145\/360825.360855","article-title":"Efficient String Matching: An Aid to Bibliographic Search","volume":"18","author":"Aho","year":"1975","journal-title":"Commun. ACM"},{"key":"ref_47","unstructured":"Yara Rules (2019, March 26). Yara Rules Official Repository. Available online: https:\/\/github.com\/Yara-Rules."},{"key":"ref_48","unstructured":"Ronen, R., Radu, M., Feuerstein, C., Yom-Tov, E., and Ahmadi, M. (arXiv, 2018). Microsoft Malware Classification Challenge, arXiv."},{"key":"ref_49","unstructured":"Offensive Computing (2019, March 26). Free Malware Download. Available online: http:\/\/www.offensivecomputing.net\/."},{"key":"ref_50","unstructured":"Virus Sign (2019, March 26). Malware Research and Data Center. Available online: http:\/\/www.virussign.com\/."},{"key":"ref_51","unstructured":"Zelter (2019, March 26). Malware Sample Sources. Available online: https:\/\/zeltser.com\/malware-sample-sources\/."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"1","DOI":"10.4236\/ait.2012.21001","article-title":"Cyber-Physical-Social Based Security Architecture for Future Internet of Things","volume":"2","author":"Ning","year":"2012","journal-title":"Adv. Internet Things"},{"key":"ref_53","unstructured":"Dorri, A., Kanhere, S., and Jurdak, R. (arXiv, 2016). Blockchain in internet of things: Challenges and Solutions, arXiv."},{"key":"ref_54","unstructured":"Tor Project (2019, March 26). Anonymity online. Available online: https:\/\/www.torproject.org\/."},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Riahi, A., Challal, Y., Natalizio, E., Chtourou, Z., and Bouabdallah, A. (2013, January 21\u201323). A Systemic Approach for IoT Security. Proceedings of the IEEE International Conference on Distributed Computing in Sensor Systems, Cambridge, MA, USA.","DOI":"10.1109\/DCOSS.2013.78"},{"key":"ref_56","unstructured":"Babar, S., Stango, A., Prasad, N., Sen, J., and Prasad, R. (March, January 28). Proposed embedded security framework for Internet of Things (IoT). Proceedings of the 2nd IEEE International Conference on Wireless Communication, Vehicular Technology, Information Theory and Aerospace & Electronic Systems Technology (Wireless VITAE), Chennai, India."},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Rahman, A.F.A., Daud, M., and Mohamad, M.Z. (2016, January 22\u201323). Securing Sensor to Cloud Ecosystem using Internet of Things (IoT) Security Framework. Proceedings of the International Conference on Internet of things and Cloud Computing\u2014ICC \u201916, Cambridge, UK.","DOI":"10.1145\/2896387.2906198"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Abie, H., and Balasingham, I. (2012, January 24\u201326). Risk-based Adaptive Security for Smart IoT in eHealth. Proceedings of the 7th International Conference on Body Area Networks (BodyNets12), Oslo, Norway.","DOI":"10.4108\/icst.bodynets.2012.250235"},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1109\/MCOM.2017.1600993","article-title":"Traffic-Aware Patching for Cyber Security in Mobile IoT","volume":"55","author":"Cheng","year":"2017","journal-title":"IEEE Commun. Mag."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Roux, J., Alata, E., Auriol, G., Nicomette, V., and Ka\u00e2niche, M. (2017, January 4\u20138). Toward an Intrusion Detection Approach for IoT based on Radio Communications Profiling. Proceedings of the 13th European Dependable Computing Conference, Geneva, Switzerland.","DOI":"10.1109\/EDCC.2017.11"},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Hodo, E., Bellekens, X., Hamilton, A., Dubouilh, P.L., Iorkyase, E., Tachtatzis, C., and Atkinson, R. (2016, January 11\u201313). Threat analysis of IoT networks using artificial neural network intrusion detection system. Proceedings of the 2016 International Symposium on Networks, Computers and Communications (ISNCC16), Hammamet, Tunisia.","DOI":"10.1109\/ISNCC.2016.7746067"},{"key":"ref_62","unstructured":"Meidan, Y., Bohadana, M., Shabtai, A., Ochoa, M., Tippenhauer, N.O., Guarnizo, J.D., and Elovici, Y. (arXiv, 2017). Detection of Unauthorized IoT Devices Using Machine Learning Techniques, arXiv."},{"key":"ref_63","first-page":"129","article-title":"Feature selection for intrusion detection using random forest","volume":"7","author":"Hasan","year":"2016","journal-title":"J. Inf. Secur."},{"key":"ref_64","first-page":"522","article-title":"IoTPOT: A Novel Honeypot for Revealing Current IoT Threats","volume":"24","author":"Pa","year":"2016","journal-title":"J. Inf. Process."},{"key":"ref_65","doi-asserted-by":"crossref","unstructured":"Sivaraman, V., Gharakheili, H.H., Vishwanath, A., Boreli, R., and Mehani, O. (2015, January 19\u201321). Network-level security and privacy control for smart-home IoT devices. Proceedings of the IEEE 11th International Conference on Wireless and Mobile Computing, Networking and Communications (WiMob15), Abu Dhabi, UAE.","DOI":"10.1109\/WiMOB.2015.7347956"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/7\/1492\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T12:40:59Z","timestamp":1760186459000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/7\/1492"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,3,27]]},"references-count":65,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2019,4]]}},"alternative-id":["s19071492"],"URL":"https:\/\/doi.org\/10.3390\/s19071492","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2019,3,27]]}}}