Secure installation of Internet of Things (IoT) devices requires configuring access control correctly for each device. In order to enable correct configuration the Manufacturer Usage Description (MUD) has been developed by Internet Engineering Task Force (IETF) to automate the protection of IoT devices by micro-segmentation using dynamic access control lists. The protocol defines a conceptually straightforward method to implement access control upon installation by providing a list of every authorized access for each device. This access control list may contain a few rules or hundreds of rules for each device. As a result, validating these rules is a challenge. In order to make the MUD standard more usable for developers, system integrators, and network operators, we report on an interactive system called MUD-Visualizer that visualizes the files containing these access control rules. We show that, unlike manual analysis, the level of the knowledge and experience does not affect the accuracy of the analysis when MUD-Visualizer is used, indicating that the tool is effective for all participants in our study across knowledge and experience levels.
翻译:安全安装物端( IoT) 装置安全安装需要为每个装置正确配置访问控制。 为了能够正确配置, Internet工程工作队(IETF)开发了制造商使用说明(MUD), 以便使用动态访问控制列表通过微分化来自动保护 IOT 装置。 协议定义了安装时实施访问控制的一种概念上直截了当的方法, 提供每个装置的每一个授权访问清单。 这个访问控制列表可能包含每个装置的几条规则或数百条规则。 因此, 验证这些规则是一项挑战。 为了使MUD 标准更便于开发者、 系统整合者和网络操作者使用, 我们在一个称为 MUD- Visualizer 的互动系统上报告, 该系统将包含这些访问控制规则的文档直观化。 我们表明, 与人工分析不同, 知识和经验的水平不会影响使用 MUD- Vuvalizer 时的分析的准确性, 表明该工具对于我们研究的所有参与者在知识和经验层面都有效 。