论文标题

朝着自动识别和阻止非关键物联网交通目的地

Towards Automatic Identification and Blocking of Non-Critical IoT Traffic Destinations

论文作者

Mandalari, Anna Maria, Kolcun, Roman, Haddadi, Hamed, Dubois, Daniel J., Choffnes, David

论文摘要

近年来,消费者互联网(IoT)领域的流行程度显着增长。从智能扬声器到婴儿监视器以及智能的水壶和电视,这些设备越来越多地在世界各地的家庭中找到,而用户可能不知道拥有这些设备的风险。先前的工作表明,这些设备可以通过在线向大量服务提供商和第三方分析服务的信息展示信息来威胁个人的隐私和安全性。我们的分析表明,其中许多Internet连接(以及它们所传达的信息)既不关键,也不是这些设备运行的必不可少的。但是,对于物联网设备的非关键网络流量,自动将关键分开是非平凡的,并且需要基于在受控环境中的手动实验的专家分析。在本文中,我们调查是否可以自动将网络流量目的地分类为关键(设备正常运行至关重要),因此允许家门口充当选择性的防火墙,以阻止不需要的非临界目的地。我们的最初结果表明,某些物联网设备与对其操作并不重要的联系目的地联系,并且如果这些目的地被阻止,则对设备功能没有影响。我们采取了设计和评估Iotrimmer的第一步,这是对设备与设备联系的各种目的地进行自动测试和分析的框架,并有选择地阻止了不影响设备功能的框架。

The consumer Internet of Things (IoT) space has experienced a significant rise in popularity in the recent years. From smart speakers, to baby monitors, and smart kettles and TVs, these devices are increasingly found in households around the world while users may be unaware of the risks associated with owning these devices. Previous work showed that these devices can threaten individuals' privacy and security by exposing information online to a large number of service providers and third party analytics services. Our analysis shows that many of these Internet connections (and the information they expose) are neither critical, nor even essential to the operation of these devices. However, automatically separating out critical from non-critical network traffic for an IoT device is nontrivial, and requires expert analysis based on manual experimentation in a controlled setting. In this paper, we investigate whether it is possible to automatically classify network traffic destinations as either critical (essential for devices to function properly) or not, hence allowing the home gateway to act as a selective firewall to block undesired, non-critical destinations. Our initial results demonstrate that some IoT devices contact destinations that are not critical to their operation, and there is no impact on device functionality if these destinations are blocked. We take the first steps towards designing and evaluating IoTrimmer, a framework for automated testing and analysis of various destinations contacted by devices, and selectively blocking the ones that do not impact device functionality.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源