Please use this identifier to cite or link to this item: https://hdl.handle.net/2440/124494
Citations
Scopus Web of Science® Altmetric
?
?
Type: Conference paper
Title: Clear as MUD: Generating, validating and applying IoT behavioral profiles
Author: Hamza, A.
Ranathunga, D.
Gharakheili, H.H.
Roughan, M.
Sivaraman, V.
Citation: Proceedings of the ACM SIGCOMM 2018 Workshop on IoT Security and Privacy (IoT S&P'18), 2018, pp.8-14
Publisher: Association for Computing Machinery
Publisher Place: New York, NY, USA
Issue Date: 2018
ISBN: 9781450359054
Conference Name: ACM SIGCOMM Workshop on IoT Security and Privacy (IoT S&P) (20 Aug 2018 : Budapest)
Statement of
Responsibility: 
Ayyoob Hamza, Dinesha Ranathunga, Hassan Habibi Gharakheili, Matthew Roughan, Vijay Sivaraman
Abstract: IoT devices are increasingly being implicated in cyber-attacks, raising community concern about the risks they pose to critical infrastructure, corporations, and citizens. In order to reduce this risk, the IETF is pushing IoT vendors to develop formal specifications of the intended purpose of their IoT devices, in the form of a Manufacturer Usage Description (MUD), so that their network behavior in any operating environment can be locked down and verified rigorously. This paper aims to assist IoT manufacturers in developing and verifying MUD profiles, while also helping adopters of these devices to ensure they are compatible with their organizational policies. Our first contribution is to develop a tool that takes the traffic trace of an arbitrary IoT device as input and automatically generates the MUD profile for it. We contribute our tool as open source, apply it to 28 consumer IoT devices, and highlight insights and challenges encountered in the process. Our second contribution is to apply a formal semantic framework that not only validates a given MUD profile for consistency, but also checks its compatibility with a given organizational policy. Finally, we apply our framework to representative organizations and selected devices, to demonstrate how MUD can reduce the effort needed for IoT acceptance testing.
Keywords: IoT; MUD; Policy Verification
Rights: © 2018 Association for Computing Machinery.
DOI: 10.1145/3229565.3229566
Grant ID: http://purl.org/au-research/grants/arc/LP150100666
Published version: http://dx.doi.org/10.1145/3229565.3229566
Appears in Collections:Aurora harvest 8
Mathematical Sciences publications

Files in This Item:
There are no files associated with this item.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.