The upcoming Internet of things (IoT) is foreseen to encompass massive numbers of connected devices, smart objects, and cyber-physical systems. Due to the large-scale and massive deployment of devices, it is deemed infeasible to safeguard 100% of the devices with state-of-the-art security countermeasures. Hence, large-scale IoT has inevitable loopholes for network intrusion and malware infiltration. Even worse, exploiting the high density of devices and direct wireless connectivity, malware infection can stealthily propagate through susceptible (i.e., unsecured) devices and form an epidemic outbreak without being noticed to security administration. A malware outbreak enables adversaries to compromise large population of devices, which can be exploited to launch versatile cyber and physical malicious attacks. In this context, we utilize spatial firewalls, to safeguard the IoT from malware outbreak. In particular, spatial firewalls are computationally capable devices equipped with state-of-the-art security and anti-malware programs that are spatially deployed across the network to filter the wireless traffic in order to detect and thwart malware propagation. Using tools from percolation theory, we prove that there exists a critical density of spatial firewalls beyond which malware outbreak is impossible. This, in turns, safeguards the IoT from malware epidemics regardless of the infection/treatment rates. To this end, a tractable upper bound for the critical density of spatial firewalls is obtained. Furthermore, we characterize the relative communications ranges of the spatial firewalls and IoT devices to ensure secure network connectivity. The percentage of devices secured by the firewalls is also characterized.
翻译:即将到来的互联网(IoT)预计将包含大量连接装置、智能物体和网络物理系统。由于大规模大规模和大规模部署装置,因此被认为无法以最先进的安全对策保护100%的装置。因此,大规模IoT不可避免地有网络入侵和恶意软件渗透的漏洞。更糟糕的是,利用高密度的装置和直接无线连接,恶意软件感染可以通过易感(即无保障)装置悄悄地传播,并形成流行病爆发,而不引起安全管理注意。恶意软件的爆发使对手能够破坏大量可使用网络和实物恶意攻击的装置。在这种情况下,我们利用空间防火墙来保护100%的装置,防止恶意软件的爆发。特别是,空间防火墙是具有可计算能力的装置,配备了最先进的安全设备和反恶意软件,通过空间部署在网络上方,以过滤无线通信,从而检测和阻止恶意软件的传播。使用透析工具,从理论,我们证明无论使用多功能来启动多功能的网络,我们都要利用空间防火墙的密度, 也证明这种防爆的密度是安全的。