Making Access Control Easy in IoT
Vafa Andalibi, Jayati Dev, DongInn Kim, Eliot Lear, L. Jean Camp

TL;DR
This paper introduces MUD-Visualizer, an interactive tool that simplifies the validation of IoT device access control rules defined by the MUD standard, making it accessible regardless of user expertise.
Contribution
The paper presents MUD-Visualizer, a novel visualization system that improves usability and accuracy in analyzing complex IoT access control lists for diverse users.
Findings
MUD-Visualizer enhances analysis accuracy across different user expertise levels.
The tool reduces the impact of user knowledge on validation accuracy.
Participants found the visualization system effective and easy to use.
Abstract
Secure installation of Internet of Things (IoT) devices requires configuring access control correctly for each device. In order to enable correct configuration the Manufacturer Usage Description (MUD) has been developed by Internet Engineering Task Force (IETF) to automate the protection of IoT devices by micro-segmentation using dynamic access control lists. The protocol defines a conceptually straightforward method to implement access control upon installation by providing a list of every authorized access for each device. This access control list may contain a few rules or hundreds of rules for each device. As a result, validating these rules is a challenge. In order to make the MUD standard more usable for developers, system integrators, and network operators, we report on an interactive system called MUD-Visualizer that visualizes the files containing these access control rules. We…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
