Attack prediction in Internet of Things using knowledge graph
Shuqin Zhang, Chunxia Zhao, Shijie Wang, Shuhan Li, Peng Chen, Yunfei Han · 2023
Internet of Things (IoT)has numerous applications in the industry and society, thanks to its ability to achieve automation and connectivity in a range of activities. Despite its great potentials, IoT is susceptible to physical and cyber-attacks, which causes security threats (e.g., financial risk and leakage of privacy). To address this problem, an approach for attack prediction is proposed for IoT. Aiming at a high degree of flexibility, an intelligent model is designed to construct knowledge graph by integrating equipment information CPE, vulnerability information CVE and attack pattern information CAPEC disclosed by the National Institute of Standards and Technology (NIST) and the security organization MITRE. Based on the knowledge graph, the safety analysis and operation analysis of many IOT information are carried out. To conclude the possible attack, knowledge representation learning method that fuses the triple information and semantic path combination information of the knowledge graph (FTSPC) was employed. We transform the attack prediction task into the link prediction problem. The suggested method is evaluated on a public dataset and our dataset, the results demonstrated that the method can predict the attack of IoT infrastructure, providing rich IoT security knowledge to security researchers and professionals and a useful reference for active defense.