IoTMonitor: A Hidden Markov Model-based Security System to Identify Crucial Attack Nodes in Trigger-action IoT Platforms
Md Morshed Alam, Md Sajidul Islam Sajid, Weichao Wang, Jinpeng Wei, (Department of Software, Information Systems, University of North Carolina, at Charlotte, Charlotte, USA)

TL;DR
IoTMonitor employs Hidden Markov Models to analyze sensor data and accurately identify critical attack nodes in trigger-action IoT platforms, enhancing security by understanding event chains and vulnerabilities.
Contribution
The paper introduces IoTMonitor, a novel HMM-based system that reconstructs event sequences and detects crucial attack nodes in IoT trigger-action scenarios, addressing security gaps in existing methods.
Findings
High accuracy in event sequence reconstruction
Effective identification of crucial attack nodes
Demonstrated success on PEEVES datasets
Abstract
With the emergence and fast development of trigger-action platforms in IoT settings, security vulnerabilities caused by the interactions among IoT devices become more prevalent. The event occurrence at one device triggers an action in another device, which may eventually contribute to the creation of a chain of events in a network. Adversaries exploit the chain effect to compromise IoT devices and trigger actions of interest remotely just by injecting malicious events into the chain. To address security vulnerabilities caused by trigger-action scenarios, existing research efforts focus on the validation of the security properties of devices or verification of the occurrence of certain events based on their physical fingerprints on a device. We propose IoTMonitor, a security analysis system that discerns the underlying chain of event occurrences with the highest probability by observing…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · User Authentication and Security Systems
