Sanitizing the IoT Cyber Security Posture: An Operational CTI Feed Backed up by Internet Measurements
Title | Sanitizing the IoT Cyber Security Posture: An Operational CTI Feed Backed up by Internet Measurements |
Publication Type | Conference Paper |
Year of Publication | 2021 |
Authors | Pour, Morteza Safaei, Watson, Dylan, Bou-Harb, Elias |
Conference Name | 2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) |
Keywords | Collaboration, composability, compositionality, cyber threat intelligence, Data Science, Feeds, Human Behavior, human factors, Internet-of-Things (IoT), Internet-scale Computing Security, IoT security, Metrics, Network telescopes, Organizations, policy-based governance, privacy, pubcrawl, Real-time Systems, resilience, Resiliency, Safety, Scalability, security, Security capabilities, Tools |
Abstract | The Internet-of-Things (IoT) paradigm at large continues to be compromised, hindering the privacy, dependability, security, and safety of our nations. While the operational security communities (i.e., CERTS, SOCs, CSIRT, etc.) continue to develop capabilities for monitoring cyberspace, tools which are IoT-centric remain at its infancy. To this end, we address this gap by innovating an actionable Cyber Threat Intelligence (CTI) feed related to Internet-scale infected IoT devices. The feed analyzes, in near real-time, 3.6TB of daily streaming passive measurements ( 1M pps) by applying a custom-developed learning methodology to distinguish between compromised IoT devices and non-IoT nodes, in addition to labeling the type and vendor. The feed is augmented with third party information to provide contextual information. We report on the operation, analysis, and shortcomings of the feed executed during an initial deployment period. We make the CTI feed available for ingestion through a public, authenticated API and a front-end platform. |
DOI | 10.1109/DSN48987.2021.00059 |
Citation Key | pour_sanitizing_2021 |
- Internet-scale Computing Security
- tools
- Security capabilities
- security
- Scalability
- Safety
- resilience
- real-time systems
- pubcrawl
- privacy
- policy-based governance
- Organizations
- Network telescopes
- IoT security
- Internet-of-Things (IoT)
- Human Factors
- Feeds
- data science
- cyber threat intelligence
- Compositionality
- collaboration
- Metrics
- Human behavior
- composability
- Resiliency