IoTEdu Core: Multi-IDS Correlation and Automated Containment of Attacks in Institutional IoT Networks

  • Emanuel Ferreira UNIPAMPA
  • Matheus Ciocca UNIPAMPA
  • Douglas Fideles UNIPAMPA
  • Tuigg Barcelos UNIPAMPA
  • Silvio Quincozes UNIPAMPA
  • Diego Kreutz UNIPAMPA

Resumo


IoTEdu Core is an open-source tool for institutional IoT networks that integrates Suricata, Snort, and Zeek alerts, correlates them by device, and enforces configurable containment through pfSense. Across 240 labeled windows covering ten attack classes and six benign profiles, orchestration increases recall from 0.67 to 0.81, while k-of-n consensus eliminates all false alarms. However, no engine detects SSH brute force, highlighting that consensus cannot address shared blind spots. We also analyze cross-family misclassifications and release the rule set, raw data, and replication scripts.

Referências

Alharbi, S. and Khan, A. (2023). Ensemble defense system: A hybrid ids approach for effective cyber threat detection. In 2023 33rd International Telecommunication Networks and Applications Conference, pages 267–270.

Alqahtani, S. et al. (2023). Cybersecurity threats in iot environments: Recent advances and challenges. Journal of Network and Computer Applications.

Boukebous, A. A. E., Fettache, M. I., Bendiab, G., and Shiaeles, S. (2023). A comparative analysis of snort 3 and suricata. In 2023 IEEE IAS Global Conference on Emerging Technologies (GlobConET), pages 1–6.

IoT Analytics (2025). State of iot 2025: Number of connected iot devices growing 13% to 21.1 billion globally. Accessed: 2026.

Katsura, Y., Sakarin, P., Yamai, N., Kimiyama, H., and Visoottiviseth, V. (2022). Quick blocking operation of firewall system cooperating with ids and sdn. In 2022 24th ICACT, pages 393–398.

Kim, J. and Lee, H. (2024). Recent advances in iot architectures and applications: A comprehensive survey. Future Generation Computer Systems.

Li, S., Xu, L. D., and Zhao, S. (2023). Security challenges and opportunities in internet of things: A survey. IEEE Internet of Things Journal.

Muhammad, A. R., Sukarno, P., and Wardana, A. A. (2023). Integrated security information and event management (siem) with intrusion detection system (ids) for live analysis based on machine learning. Procedia Computer Science, 217:1406–1415. ISM 2022.

Nguyen, T. et al. (2024). Security and privacy challenges in iot-based smart environments. Computer Networks.

OSSIM (2026). OSSIM: AlienVault’s open source SIEM. levelblue. Ouiazzane, S., Addou, M., and Barramou, F. (2022). A suricata and machine learning based hybrid network intrusion detection system. In Maleh, Y., Alazab, M., Gherabi, N., Tawalbeh, L., and Abd El-Latif, A. A., editors, Advances in Information, Communication and Cybersecurity, pages 474–485, Cham. Springer International Publishing.

Praptodiyono, S., Firmansyah, T., Anwar, M. H., Wicaksana, C. A., Pramudyo, A. S., and Al-Allawee, A. (2023). Development of hybrid intrusion detection system based on suricata with pfsense method for high reduction of ddos attacks on ipv6 networks. Eastern-European Journal of Enterprise Technologies, 5(9 (125)):75–84.

Qutqut, M. H., Ahmed, A., Taqi, M. K., Abimanyu, J., Ajes, E. T., and Alhaj, F. (2026). A comparative evaluation of snort and suricata for detecting data exfiltration tunnels in cloud environments. Journal of Cybersecurity and Privacy, 6(1).

Rahman, M. et al. (2023). Edge computing for iot: Security and scalability challenges. IEEE Communications Surveys & Tutorials.

Security Onion (2026). Security onion: A free and open platform for threat hunting, network security monitoring, and log management. security onion solutions, llc.

Waleed, A., Jamali, A. F., and Masood, A. (2022). Which open-source ids? snort, suricata or zeek. Computer Networks, 213:109116.

Wazuh (2026). Wazuh: The open source security platform — unified XDR and SIEM protection for endpoints and cloud workloads.
Publicado
01/09/2026
FERREIRA, Emanuel; CIOCCA, Matheus; FIDELES, Douglas; BARCELOS, Tuigg; QUINCOZES, Silvio; KREUTZ, Diego. IoTEdu Core: Multi-IDS Correlation and Automated Containment of Attacks in Institutional IoT Networks. In: SALÃO DE FERRAMENTAS - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 156-165. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33721.

Artigos mais lidos do(s) mesmo(s) autor(es)

<< < 6 7 8 9 10 11 12 > >>