Title
Sanitizing the IoT Cyber Security Posture: An Operational CTI Feed Backed up by Internet Measurements
Abstract
The Internet-of-Things (IoT) paradigm at large continues to be compromised, hindering the privacy, dependability, security, and safety of our nations. While the operational security communities (i.e., CERTS, SOCs, CSIRT, etc.) continue to develop capabilities for monitoring cyberspace, tools which are IoT-centric remain at its infancy. To this end, we address this gap by innovating an actionable Cyber Threat Intelligence (CTI) feed related to Internet-scale infected IoT devices. The feed analyzes, in near real-time, 3.6TB of daily streaming passive measurements ( ≈ 1M pps) by applying a custom-developed learning methodology to distinguish between compromised IoT devices and non-IoT nodes, in addition to labeling the type and vendor. The feed is augmented with third party information to provide contextual information. We report on the operation, analysis, and shortcomings of the feed executed during an initial deployment period. We make the CTI feed available for ingestion through a public, authenticated API and a front-end platform.
Year
DOI
Venue
2021
10.1109/DSN48987.2021.00059
2021 51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
Keywords
DocType
ISSN
Internet-of-Things (IoT),Cyber Threat Intelligence,Security capabilities,Network telescopes,Data science
Conference
1530-0889
ISBN
Citations 
PageRank 
978-1-6654-1194-3
1
0.37
References 
Authors
0
3
Name
Order
Citations
PageRank
Morteza Safaei Pour141.81
Dylan Watson210.37
Elias Bou-Harb320726.40