{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T00:10:03Z","timestamp":1778631003653,"version":"3.51.4"},"reference-count":51,"publisher":"MDPI AG","issue":"22","license":[{"start":{"date-parts":[[2021,11,15]],"date-time":"2021-11-15T00:00:00Z","timestamp":1636934400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Nowadays, there are different kinds of public knowledge bases for cyber security vulnerability and threat intelligence which can be used for IoT security threat analysis. However, the heterogeneity of these knowledge bases and the complexity of the IoT environments make network security situation awareness and threat assessment difficult. In this paper, we integrate vulnerabilities, weaknesses, affected platforms, tactics, attack techniques, and attack patterns into a coherent set of links. In addition, we propose an IoT security ontology model, namely, the IoT Security Threat Ontology (IoTSTO), to describe the elements of IoT security threats and design inference rules for threat analysis. This IoTSTO expands the current knowledge domain of cyber security ontology modeling. In the IoTSTO model, the proposed multi-source knowledge reasoning method can perform the following tasks: assess the threats of the IoT environment, automatically infer mitigations, and separate IoT nodes that are subject to specific threats. The method above provides support to security managers in their deployment of security solutions. This paper completes the association of current public knowledge bases for IoT security and solves the semantic heterogeneity of multi-source knowledge. In this paper, we reveal the scope of public knowledge bases and their interrelationships through the multi-source knowledge reasoning method for IoT security. In conclusion, the paper provides a unified, extensible, and reusable method for IoT security analysis and decision making.<\/jats:p>","DOI":"10.3390\/s21227579","type":"journal-article","created":{"date-parts":[[2021,11,15]],"date-time":"2021-11-15T20:46:47Z","timestamp":1637009207000},"page":"7579","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["Multi-Source Knowledge Reasoning for Data-Driven IoT Security"],"prefix":"10.3390","volume":"21","author":[{"given":"Shuqin","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computer Science, Zhongyuan University of Technology, Zhengzhou 450007, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3735-1210","authenticated-orcid":false,"given":"Guangyao","family":"Bai","sequence":"additional","affiliation":[{"name":"School of Computer Science, Zhongyuan University of Technology, Zhengzhou 450007, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hong","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peipei","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Minzhi","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, Zhongyuan University of Technology, Zhengzhou 450007, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shujun","family":"Li","sequence":"additional","affiliation":[{"name":"School of Information Science and Technology, Yancheng Teachers University, Yancheng 224002, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,11,15]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.comcom.2014.09.008","article-title":"The internet of things vision: Key features, applications and open issues","volume":"1","author":"Borgia","year":"2014","journal-title":"Comput. Commun."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1109\/MSEC.2018.2888780","article-title":"The internet of things promises new benefits and risks: A systematic analysis of adoption dynamics of IoT products","volume":"17","author":"Mohammad","year":"2019","journal-title":"IEEE Secur. Priv."},{"key":"ref_3","unstructured":"(2021, October 27). CISA: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations, Available online: https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-352a."},{"key":"ref_4","unstructured":"(2021, October 27). SECURELIST by Kaspersky: Popular Server Management Software Hit in Supply Chain Attack. Available online: https:\/\/securelist.com\/shadowpad-in-corporate-networks\/81432\/."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1385","DOI":"10.1109\/TII.2019.2950109","article-title":"Smart collaborative automation for receive buffer control in multipath industrial networks","volume":"16","author":"Song","year":"2020","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1125","DOI":"10.1109\/JIOT.2017.2683200","article-title":"A survey on internet of things: Architecture, enabling technologies, security and privacy, and applications","volume":"4","author":"Lin","year":"2017","journal-title":"IEEE Internet Things J."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Schinagl, S., Schoon, K., and Paans, R. (2015, January 5\u20138). A framework for designing a security operations centre (SOC). Proceedings of the 2015 48th Hawaii International Conference on System Sciences (HICSS), Washington, DC, USA.","DOI":"10.1109\/HICSS.2015.270"},{"key":"ref_8","first-page":"1","article-title":"D-BRIDEMAID: A distributed framework for collaborative and dynamic analysis of android malware","volume":"11","author":"Antonio","year":"2020","journal-title":"JoWUA"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Zeshan, F., Ahmad, A., Abdel-Aty, A.-H., Algarni, F., Mahmoud, E.E., and Ahmad, A. (2020). A hybrid semantic knowledge integration and sharing approach for distributed smart environments. Sensors, 20.","DOI":"10.3390\/s20205918"},{"key":"ref_10","first-page":"31","article-title":"Towards detecting and classifying malicious URLs using deep learning","volume":"11","author":"Clayton","year":"2020","journal-title":"JoWUA"},{"key":"ref_11","first-page":"35","article-title":"Fine-hearing Google Home: Why silence will not protect your privacy","volume":"11","author":"Davide","year":"2020","journal-title":"JoWUA"},{"key":"ref_12","unstructured":"Syed, Z., Padia, A., Finin, T., Mathews, L., and Joshi, A. (2016, January 12). UCO: A unified cybersecurity ontology. Proceedings of the 2016 AAAI Workshop on Artificial Intelligence for Cyber Security, Menlo Park, CA, USA."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Abbas, S.G., Vaccari, I., Hussain, F., Zahid, S., Fayyaz, U.U., Shah, G.A., Bakhshi, T., and Cambiaso, E. (2021). Identifying and mitigating phishing attack threats in IoT use cases using a threat modelling approach. Sensors, 21.","DOI":"10.3390\/s21144816"},{"key":"ref_14","first-page":"836","article-title":"Cyber security threat intelligence sharing model based on blockchain","volume":"57","author":"Huang","year":"2020","journal-title":"J. Comput. Res. Dev."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Kiesling, E., Ekelhart, A., Kurniawan, K., and Ekaputra, F. (2019, January 26\u201330). The SEPSES knowledge graph: An integrated resource for cybersecurity. Proceedings of the Semantic Web\u2014ISWC 2019, Auckland, New Zealand.","DOI":"10.1007\/978-3-030-30796-7_13"},{"key":"ref_16","first-page":"731","article-title":"Threat propagation based security situation quantitative assessment in multi-node network","volume":"54","author":"Tian","year":"2017","journal-title":"J. Comput. Res. Dev."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1016\/j.eng.2018.01.004","article-title":"A practical approach to constructing a knowledge graph for cybersecurity","volume":"4","author":"Jia","year":"2018","journal-title":"Engineering"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Rastogi, N., Dutta, S., Zaki, M.J., Gittens, A., and Aggarwal, C. (2020). MALOnt: An ontology for malware threat intelligence. arXiv.","DOI":"10.1007\/978-3-030-59621-7_2"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Mozzaquatro, B., Goncalves, R.J., and Agostinho, C. (2015, January 12\u201313). Towards a reference ontology for security in the internet of things. Proceedings of the 2015 IEEE International Workshop on Measurements & Networking, Coimbra, Portugal.","DOI":"10.1109\/IWMN.2015.7322984"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"110510","DOI":"10.1109\/ACCESS.2019.2933859","article-title":"Ontology-based security context reasoning for power IoT-cloud security service","volume":"7","author":"Choi","year":"2019","journal-title":"IEEE Access"},{"key":"ref_21","first-page":"173","article-title":"Research on network security situational elements knowledge base model based on ontology","volume":"42","author":"Si","year":"2015","journal-title":"Comput. Sci."},{"key":"ref_22","first-page":"39","article-title":"Ontology model based on security parameters capturing process for network systems","volume":"3","author":"Li","year":"2017","journal-title":"Chin. J. Netw. Inf. Secur."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Mozzaquatro, B., Agostinho, C., Goncalves, D., Martins, J., and Goncalves, R.J. (2018). An ontology-based cybersecurity framework for the internet of things. Sensors, 18.","DOI":"10.3390\/s18093053"},{"key":"ref_24","unstructured":"Igor, T., and Petra, G. (2020, January 28). Towards the open ontology for IoT ecosystem\u2019s security. Proceedings of the 2020 43rd International Convention on Information, Communication and Electronic Technology (MIPRO), Opatija, Croatia."},{"key":"ref_25","unstructured":"MITRE (2020, December 15). Common Vulnerabilities and Exposure. Available online: https:\/\/cve.mitre.org\/."},{"key":"ref_26","unstructured":"NIST (2020, December 15). National Vulnerability Databased, Available online: https:\/\/nvd.nist.gov."},{"key":"ref_27","unstructured":"MITRE (2020, December 15). Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/."},{"key":"ref_28","unstructured":"MITRE (2020, December 15). Common Attack Pattern Enumeration and Classification. Available online: https:\/\/capec.mitre.org\/."},{"key":"ref_29","unstructured":"NIST (2020, December 15). Common Platform Enumeration, Available online: https:\/\/nvd.nist.gov\/Products\/CPE."},{"key":"ref_30","unstructured":"MITRE (2020, December 15). ATT&CK Matrix for Enterprise. Available online: https:\/\/attack.mitre.org\/."},{"key":"ref_31","unstructured":"FIRST (2020, December 15). Common Vulnerability Scoring System. Available online: https:\/\/www.first.org\/cvss\/."},{"key":"ref_32","unstructured":"MITRE (2020, December 15). Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/about\/index.html."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Cheng, X., Zhang, J., and Chen, B. (2019). Cyber situation comprehension for IoT systems based on APT alerts and logs correlation. Sensors, 19.","DOI":"10.3390\/s19184045"},{"key":"ref_34","first-page":"56","article-title":"Knowledge graph for cyberspace security intelligence: A survey","volume":"5","author":"Dong","year":"2020","journal-title":"J. Cyber Secur."},{"key":"ref_35","first-page":"3","article-title":"Why would we get attacked? An analysis of attacker\u2019s aims behind DDoS attacks","volume":"11","author":"Abhishta","year":"2020","journal-title":"JoWUA"},{"key":"ref_36","first-page":"37","article-title":"Research of threat intelligence sharing and using for cyber attack attribution","volume":"1","author":"Yang","year":"2015","journal-title":"J. Inf. Secur. Res."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"6046","DOI":"10.1109\/JIOT.2019.2958097","article-title":"Smart collaborative tracking for ubiquitous power IoT in edge-cloud interplay domain","volume":"7","author":"Song","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_38","first-page":"49","article-title":"Detection and classification of radio frequency jamming attacks using machine learning","volume":"11","author":"Kasturi","year":"2020","journal-title":"JoWUA"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"21046","DOI":"10.1109\/ACCESS.2017.2734681","article-title":"Network security situation awareness based on semantic ontology and user-defined rules for internet of things","volume":"5","author":"Xu","year":"2017","journal-title":"IEEE Access"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"1589","DOI":"10.1109\/ACCESS.2017.2663407","article-title":"Towards ontological approach on trust-aware ambient services","volume":"5","author":"Lee","year":"2017","journal-title":"IEEE Access"},{"key":"ref_41","first-page":"507","article-title":"Segmentation-based image copy-move forgery detection scheme","volume":"10","author":"Li","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_42","unstructured":"(2021, March 17). W3C Semantic Web. Available online: https:\/\/www.w3.org\/OWL\/."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Qin, S.Z., and Chow, K.P. (2019). Automatic analysis and reasoning based on vulnerability knowledge graph. Cyberspace Data and Intelligence, and Cyber-Living, Syndrome, and Health, Springer.","DOI":"10.1007\/978-981-15-1922-2_1"},{"key":"ref_44","unstructured":"Ian, H., Peter, F.P., Harold, B., Said, T., Benjamin, G., and Mike, D. (2021, April 15). SWRL: A Semantic Web Rule Language Combining OWL and RuleML. Available online: http:\/\/www.daml.org\/rules\/proposal\/."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Peng, C., and Goswami, P. (2019). Meaningful integration of data from heterogeneous health services and home environment based on ontology. Sensors, 19.","DOI":"10.3390\/s19081747"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1109\/MNET.011.2000613","article-title":"Enabling heterogeneous deterministic networks with smart collaborative theory","volume":"35","author":"Song","year":"2021","journal-title":"IEEE Netw."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"6916","DOI":"10.1109\/TII.2020.3029766","article-title":"Smart collaborative balancing for dependable network components in cyber-physical systems","volume":"17","author":"Song","year":"2021","journal-title":"IEEE Trans. Industr. Inform."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"593","DOI":"10.1016\/j.ins.2018.06.002","article-title":"Smart collaborative distribution for privacy enhancement in moving target defense","volume":"479","author":"Song","year":"2019","journal-title":"Inform. Sci."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Shang, H.J., Rong, J., Li, A.P., and Wei, W. (2017, January 26\u201329). A framework to construct knowledge base for cyber security. Proceedings of the 2017 IEEE Second International Conference on Data Science in Cyberspace, Shenzhen, China.","DOI":"10.1109\/DSC.2017.55"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Zhu, L.N., Zhang, Z.C., Xia, G.E., and Jiang, C. (2019, January 24\u201326). Research on vulnerability ontology model. Proceedings of the 2019 IEEE 8th Joint International Information Technology and Artificial Intelligence Conference (ITAIC), Chongqing, China.","DOI":"10.1109\/ITAIC.2019.8785783"},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Qi, Y.L., Jiang, R., Jia, Y., and Li, A. (2020). Attack analysis framework for cyber-attack and defense test platform. Electronics, 9.","DOI":"10.3390\/electronics9091413"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/22\/7579\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:30:24Z","timestamp":1760167824000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/22\/7579"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,15]]},"references-count":51,"journal-issue":{"issue":"22","published-online":{"date-parts":[[2021,11]]}},"alternative-id":["s21227579"],"URL":"https:\/\/doi.org\/10.3390\/s21227579","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,15]]}}}