Hardening the Internet of Things: Toward Designing Access Control For Resource Constrained IoT Devices
Manuel Bessler, Paul Sangster, Radhika Upadrashta, TJ OConnor · 2024
A myriad of security and privacy threats have accompanied the rapid proliferation and widespread adoption of Internet-of-Things (IoT) devices. IoT vendors often justify this challenge by citing the difficulty of securing resource-constrained embedded devices. However, the monolithic nature of IoT devices introduces the opportunity to leverage mandatory and role-based access control to create a comprehensive yet flexible access control design. We identify that the TOMOYO and CaitSith Linux Security Modules offer opportunities to implement practical access control policies for IoT but there is a dearth of publications in this area. In the following work, we design and implement an access control approach for a Linux-based IoT gateway. Specifically, we explore how to reduce the attack surface by defining the policies to restrict the device to the minimum required behaviors. We empirically evaluate our approach’s ability to withstand a network penetration test. Through these efforts, we demonstrate the capacity of Linux security modules to enforce access control on resource-constrained IoT devices.