Related Experiment Video
Updated: Jan 19, 2026

Implementation of a Real-Time Psychosis Risk Detection and Alerting System Based on Electronic Health Records using CogStack
Published on: May 15, 2020
Cyber Situation Comprehension for IoT Systems based on APT Alerts and Logs Correlation
Xiang Cheng1,2, Jiale Zhang3,4, Bing Chen5,6
1College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106, China. huozhai9527@126.com.
This study introduces APTALCM, a novel method for Advanced Persistent Threat (APT) detection in IoT systems. It effectively correlates alerts and logs to comprehend cyber situations and identify attack intentions with high accuracy.
Area of Science:
- Cybersecurity
- Internet of Things (IoT) Security
- Network Intrusion Detection
Background:
- Advanced Persistent Threats (APTs) pose significant, concealed threats to IoT systems.
- Existing detection methods lack comprehensive and prompt recognition capabilities for APT activities in IoT environments.
- High data transmission costs hinder effective cyber situation comprehension in distributed IoT systems.
Purpose of the Study:
- To propose a novel APT Alerts and Logs Correlation Method (APTALCM) for enhanced IoT security.
- To develop a framework for deploying APTALCM using edge computing for efficient cyber situation comprehension.
- To accurately recognize APT attack intentions within IoT systems.
Main Methods:
- Developed a cyber situation ontology for formalizing APT attack activities in IoT.
- Implemented a SimRank-based similarity measurement for correlating APT alerts and logs.
- Proposed Alert Instance Correlation Module (AICM) and Log Instance Correlation Module (LICM) for scenario reconstruction and log community detection.
Main Results:
- APTALCM effectively achieves cyber situation comprehension by recognizing APT attack intentions.
- The AICM and LICM modules demonstrate a high true-positive rate and a low false-positive rate.
- Edge computing architecture minimizes data transmission costs while enabling effective threat detection.
Conclusions:
- APTALCM provides a comprehensive and prompt solution for detecting APT activities in IoT systems.
- The proposed method enhances cybersecurity posture by enabling accurate identification of attack intentions.
- The framework's edge computing approach is crucial for scalable and cost-effective IoT security.
Related Concept Videos
Control Systems
At the heart...
Integration of Synaptic Events
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Distributed Loads: Problem Solving
Distribution Reliability and Automation
Signal and System
