Cyber‐Securing IoT Infrastructure by Modeling Network Traffic

Hassan Habibi Gharakheili, Ayyoob Hamza, Vijay Sivaraman · 2021

In recent years, there has been growing recognition that machine learning is not a “silver bullet” that can magically detect all cyber-security threats, but is instead more effective in a narrower context – when the threat model is clear and the scope of the target activity is narrow. This chapter begins by highlighting Internet-of-Things (IoT) network threats and attack vectors, as well as existing countermeasures and their limitations. Next, a systematic approach to model the network behavior of IoT devices is developed, automatically enforcing their behavior and monitoring real-time activity using a set of flow-based anomaly detectors. The chapter outlines Software-Defined Networking-based system to enforce Manufacturer Usage Description (MUD) policies and dynamically inspect exception traffic (nonconforming to MUD profile) which is a small fraction of total packets to/from IoT devices.

Read the paper · More papers on PaperTik