Monitoring your system

There are many challenges to monitoring your IoT system. For example, some devices may not generate security audit logs, and many devices do not support formats such as syslog. Gaining timely access to device log data can prove difficult, and the confidence in the integrity of IoT device audit logs may be limited, given minimal, if any, protection mechanisms applied to the logs. Even so, there are events that should be monitored within an IoT system. Any of these events on their own are not necessarily an indicator of compromise; however, security analysts should correlate events across the system to determine if further investigation is required. Some events to monitor within an IoT system include: 

  • Device not reachable ...

Get Practical Internet of Things Security - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.