Identification Management for Zero Trust Through Network Analysis

Amal Alshehri, Burak Tüfekçi, Cihan Tunc · 2024

Internet of Things (IoT) and Operational Technology (OT) are becoming essential parts of next-generation smart environments, including Industry 4.0 thanks to their capabilities of monitoring and/or controlling industrial devices, processes, and events. It is expected that there will be around 75 billion such devices, especially considering 5G (and 6G in the future) networking. However, security is one of the major concerns, especially because most legacy devices/equipment have little to no security measures applied. And, replacing all the equipment with new ones continuously is not a feasible solution to enforce security measures. One alternative is enforcing Zero Trust Architecture (ZTA) principles in these environments based on the “never trust, always verify” principle. Applying ZT for an OT environment through its network (by continuously monitoring and checking the activities based on ZTA-based policies) can improve the sustainability and security of the IoT/OT-based environments because no major changes would be needed in the existing infrastructures while improving security. For this reason, we propose an architecture that monitors the network behavior and compares them with the devices' proposed identities (their IP and MAC addresses). We first monitor the network behaviors, create flows, and select the best features. Then, we identify the individual devices using supervised machine learning techniques such as Gradient Boosting Classifier as they are lightweight and fast in detection compared to alternatives. Our results show high accuracy, precision, and recall values in our experiments. Using different scenarios, we evaluated our idea and if a device behaves differently than the proposed behavior, we are able to detect and put a firewall rule that blocks the device network traffic on the gateway.

Read the paper · More papers on PaperTik