Supervising Smart Home Device Interactions: A Profile-Based Firewall Approach
Fran\c{c}ois De Keersmaeker, Ramin Sadre, Cristel Pelsser

TL;DR
This paper introduces a new expressive language for describing smart home device traffic patterns, enabling more effective firewall configurations that improve security without impacting performance.
Contribution
It presents a novel language for device profiles that surpasses MUD's expressiveness and translates them into efficient firewall rules for enhanced security.
Findings
Accurately blocks unwanted device traffic
Negligible latency impact on network performance
Effective in diverse Smart Home device scenarios
Abstract
Internet of Things devices can now be found everywhere, including in our households in the form of Smart Home networks. Despite their ubiquity, their security is unsatisfactory, as demonstrated by recent attacks. The IETF's MUD standard has as goal to simplify and automate the secure deployment of end devices in networks. A MUD file contains a device specific description of allowed network activities (e.g., allowed IP ports or host addresses) and can be used to configure for example a firewall. A major weakness of MUD is that it is not expressive enough to describe traffic patterns representing device interactions, which often occur in modern Smart Home platforms. In this article, we present a new language for describing such traffic patterns. The language allows writing device profiles that are more expressive than MUD files and take into account the interdependencies of traffic…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Network Security and Intrusion Detection · IPv6, Mobility, Handover, Networks, Security
