Intrusion Detection on IoT Services using Event Network Correlation

이벤트 네트워크 상관분석을 이용한 IoT 서비스에서의 침입탐지

  • Park, Boseok (School of Computer Science and Engineering, Graduate School, Kyungpook National University) ;
  • Kim, Sangwook (School of Computer Science and Engineering, Graduate School, Kyungpook National University)
  • Received : 2019.09.08
  • Accepted : 2019.12.23
  • Published : 2020.01.31


As the number of internet-connected appliances and the variety of IoT services are rapidly increasing, it is hard to protect IT assets with traditional network security techniques. Most traditional network log analysis systems use rule based mechanisms to reduce the raw logs. But using predefined rules can't detect new attack patterns. So, there is a need for a mechanism to reduce congested raw logs and detect new attack patterns. This paper suggests enterprise security management for IoT services using graph and network measures. We model an event network based on a graph of interconnected logs between network devices and IoT gateways. And we suggest a network clustering algorithm that estimates the attack probability of log clusters and detects new attack patterns.


Supported by : Kyungpook National University


