As the prevalence of Internet-of-Things (IoT) devices becomes more and more dominant, so too do the associated management and security challenges. One such challenge is the exploitation of vulnerable devices for recruitment into botnets, which can be used to carry out Distributed Denial-of-Service (DDoS) attacks. The recent Manufacturer Usage Description (MUD) standard has been proposed as a way to mitigate this problem, by allowing manufacturers to define communication patterns that are permitted for their IoT devices, with enforcement at the gateway home router. In this paper, we present a novel integrated system implementation that uses a MUD manager (osMUD) to parse an extended set of MUD rules, which also allow for rate-limiting of traffic and for setting appropriate thresholds. Additionally, we present two new backends for MUD rule enforcement, one based on eBPF and the other based on the Linux standard iptables. The reported evaluation results show that these techniques are feasible and effective in protecting against attacks and in terms of their impact on legitimate traffic and on the home gateway.
翻译:随着物联网设备日益普及,相关的管理与安全挑战也随之增加。其中一个挑战是,脆弱设备可能被利用并招募为僵尸网络成员,进而实施分布式拒绝服务(DDoS)攻击。近期提出的制造商使用说明(MUD)标准旨在缓解这一问题,其允许制造商定义物联网设备的许可通信模式,并在家庭网关路由器上强制执行。本文提出了一种新型集成系统实现方案,利用MUD管理器(osMUD)解析扩展后的MUD规则集,该规则集支持流量速率限制及设置适当阈值。此外,我们提出了两种新的MUD规则执行后端方案,分别基于eBPF和Linux标准iptables。评估结果表明,这些技术在防御攻击方面切实可行且有效,同时能够兼顾对合法流量及家庭网关性能的影响。