DEMONS: Extended Manufacturer Usage Description to Restrain Malicious Smartphone Apps

Ina Berenice Fink, Martin Serror, Klaus Wehrle · 2021

The growing popularity of the consumer IoT intensifies the risks for security and privacy breaches. It typically suffices to successfully attack a single IoT device to access the home network illicitly. This observation emphasizes the need for in-network security, complementing each device’s security mechanisms with additional network-layer protection. Recently, the IETF proposed Manufacturer Usage Description (MUD) to limit network traffic of IoT devices to their required minimum. However, the tangled communication of IoT devices, e.g., connections to smartphones and smart speakers, is not covered by MUD. We propose Distributed Enforcement of MUD on Smartphones (DEMONS), extending central enforcement of MUD with distributed enforcement at authenticated smartphones to mitigate the threats of malicious apps and IoT devices by filtering malicious traffic close to its origin and preventing further spread. We discuss the security gains and demonstrate that the introduced overhead regarding latency, bandwidth, and power consumption has a negligible performance impact.

Read the paper · More papers on PaperTik