IoT environments increase the attack surface and challenge incident response. IoTEdu orchestrates multiple IDSs (Suricata, Snort, Zeek) in a unified pipeline with event correlation and automated blocking. Across five attack types (75 runs), it achieves 5.56s average containment, with latency dominated by detection. Results expose a trade-off between signature-based speed and behavior-based context, showing that multi-IDS orchestration improves automated response in dynamic IoT settings.
Assolin et al. (Sun,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: