Visible to the public Sanitizing the IoT Cyber Security Posture: An Operational CTI Feed Backed up by Internet Measurements

TitleSanitizing the IoT Cyber Security Posture: An Operational CTI Feed Backed up by Internet Measurements
Publication TypeConference Paper
Year of Publication2021
AuthorsPour, Morteza Safaei, Watson, Dylan, Bou-Harb, Elias
Conference Name2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
KeywordsCollaboration, composability, compositionality, cyber threat intelligence, Data Science, Feeds, Human Behavior, human factors, Internet-of-Things (IoT), Internet-scale Computing Security, IoT security, Metrics, Network telescopes, Organizations, policy-based governance, privacy, pubcrawl, Real-time Systems, resilience, Resiliency, Safety, Scalability, security, Security capabilities, Tools
Abstract

The Internet-of-Things (IoT) paradigm at large continues to be compromised, hindering the privacy, dependability, security, and safety of our nations. While the operational security communities (i.e., CERTS, SOCs, CSIRT, etc.) continue to develop capabilities for monitoring cyberspace, tools which are IoT-centric remain at its infancy. To this end, we address this gap by innovating an actionable Cyber Threat Intelligence (CTI) feed related to Internet-scale infected IoT devices. The feed analyzes, in near real-time, 3.6TB of daily streaming passive measurements ( 1M pps) by applying a custom-developed learning methodology to distinguish between compromised IoT devices and non-IoT nodes, in addition to labeling the type and vendor. The feed is augmented with third party information to provide contextual information. We report on the operation, analysis, and shortcomings of the feed executed during an initial deployment period. We make the CTI feed available for ingestion through a public, authenticated API and a front-end platform.

DOI10.1109/DSN48987.2021.00059
Citation Keypour_sanitizing_2021