SERENIoT: Distributed Network Security Policy Management and Enforcement for Smart Homes

被引:1
|
作者
Thomasset, Corentin [1 ]
Barrera, David [2 ]
机构
[1] Polytech Montreal, Montreal, PQ, Canada
[2] Carleton Univ, Ottawa, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
IoT security; traffic filtering; intrusion detection; blockchain; INTERNET;
D O I
10.1145/3427228.3427235
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Selectively allowing network traffic has emerged as a dominant approach for securing consumer IoT devices. However, determining what the allowed behavior of an IoT device should be remains an open challenge. Proposals to date have relied on manufacturers and trusted parties to provide allow lists of network traffic, but these proposals require manufacturer involvement or placing trust in an additional stakeholder. Alternatively, locally monitoring devices can allow building allow lists of observed behavior, but devices may not exhaust their functionality set during the observation period, and the behavior may change following a software update which requires re-training. This paper proposes a blockchain-based system for determining whether an IoT device is behaving like other devices of the same type. Our system, SERENIoT, overcomes the challenge of initially determining the correct behavior for a device. Nodes in the SERENIoT public blockchain submit summaries of the network behavior observed for connected IoT devices and build allow lists of behavior observed by the majority of nodes. Changes in behavior through software updates are automatically added to the allow list once the update is broadly deployed. Through a proofof-concept implementation of SERENIoT on a small IoT network and a large-scale Amazon EC2 simulation, we evaluate the security, scalability, and performance of our system.
引用
收藏
页码:542 / 555
页数:14
相关论文
共 50 条
  • [1] Security policy enforcement for networked smart objects
    Sicari, Sabrina
    Rizzardi, Alessandra
    Miorandi, Daniele
    Cappiello, Cinzia
    Coen-Porisini, Alberto
    [J]. COMPUTER NETWORKS, 2016, 108 : 133 - 147
  • [2] Transparent network security policy enforcement
    Keromytis, AD
    Wright, JL
    [J]. USENIX ASSOCIATION PROCEEDINGS OF THE FREENIX TRACK, 2000, : 215 - 225
  • [3] Towards In-Network Security for Smart Homes
    Serror, Martin
    Henze, Martin
    Hack, Sacha
    Schuba, Marko
    Wehrle, Klaus
    [J]. 13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,
  • [4] Distributed optimal power management for smart homes in microgrids with network and communication constraints
    Kang, Wenfa
    Liao, Jianquan
    Chen, Minyou
    Sun, Kai
    Tavner, Peter J.
    Guerrero, Josep M.
    [J]. APPLIED ENERGY, 2024, 375
  • [5] MSNetViews: Geographically Distributed Management of Enterprise Network Security Policy
    Anjum, Iffat
    Sokal, Jessica
    Rehman, Hafiza Ramzah
    Weintraub, Ben
    Leba, Ethan
    Enck, William
    Nita-Rotaru, Cristina
    Reaves, Bradley
    [J]. PROCEEDINGS OF THE 28TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, SACMAT 2023, 2023, : 121 - 132
  • [6] Distributed Middleware Enforcement of Event Flow Security Policy
    Migliavacca, Matteo
    Papagiannis, Ioannis
    Eyers, David M.
    Shand, Brian
    Bacon, Jean
    Pietzuch, Peter
    [J]. MIDDLEWARE 2010, 2010, 6452 : 334 - +
  • [7] If-This-Then-Allow-That (to Phone Home): A Trigger-Based Network Policy Enforcement Framework for Smart Homes
    Tam, Anthony
    Alaca, Furkan
    Barrera, David
    [J]. FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2022, 2023, 13877 : 373 - 388
  • [8] Efficient Network Security Policy Enforcement With Policy Space Analysis
    Wang, Xiang
    Shi, Weiqi
    Xiang, Yang
    Li, Jun
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2016, 24 (05) : 2958 - 2970
  • [9] DiSPEL: A Framework for SoC Security Policy Synthesis and Distributed Enforcement
    Paria, Sudipta
    Dasgupta, Aritra
    Bhunia, Swarup
    [J]. 2024 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST, HOST, 2024, : 271 - 281
  • [10] Security network policy enforcement through a SDN framework
    Berardi, Davide
    Callegati, Franco
    Melis, Andrea
    Prandini, Marco
    [J]. 2018 28TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2018, : 97 - 100