Detail výsledku
Security Monitoring of IoT Communication Using Flows
        MATOUŠEK, P.; RYŠAVÝ, O.; GRÉGR, M. Security Monitoring of IoT Communication Using Flows. In Proceedings of the 6th Conference on the Engineering of Computer Based Systems. ECBS '19. New York: Association for Computing Machinery, 2019. p. 1-9.  ISBN: 978-1-4503-7636-5.
    
                Typ
            
        
                článek ve sborníku konference
            
        
                Jazyk
            
        
                anglicky
            
        
            Autoři
            
        
                Matoušek Petr, doc. Ing., Ph.D., M.A., UIFS (FIT)
                
Ryšavý Ondřej, doc. Ing., Ph.D., UIFS (FIT)
Grégr Matěj, Ing., Ph.D., CVIS ‒ Sítě (CIS), UIFS (FIT)
        Ryšavý Ondřej, doc. Ing., Ph.D., UIFS (FIT)
Grégr Matěj, Ing., Ph.D., CVIS ‒ Sítě (CIS), UIFS (FIT)
                    Abstrakt
            
        Network monitoring is an important part of network management that collects valuable metadata describing active communication protocols, network transmissions, bandwidth utilization, and the most communicating nodes. Traditional IP network monitoring techniques include the SNMP system, flow monitoring, or system logging. The environment of the Internet of Things (IoT) networks, however, shows that these approaches do not provide sufficient visibility of IoT communication which would allow network administrators to identify possible attacks on IoT nodes. The reason is obvious: IoT devices lack sufficient computational resources to fully implement monitoring agents, LAN IoT data communication is often directly over data link layers rather than IP, and IoT sensors produce an endless flow of small packets which can be difficult to process in real-time. To tackle these limitations we propose a new IoT monitoring model based on extended IPFIX records. The model employs a passive monitoring probe that observes IoT traffic and collects metadata from IoT protocols. Using extended IPFIX protocol, flow records with IoT metadata are sent to the collector where they are analyzed and used to provide a global view on the whole IoT network and its communication. We also present two statistical approaches that analyze IoT flows data in order to detect security incidents or malfunctioning of a device. The proof-of-concept implementation is demonstrated for Constrained Application Protocol (CoAP) traffic in the smart home environment.
                Klíčová slova
            
        Internet of Things, security, monitoring, statistical anomaly detection,
IPFIX, CoAP
                URL
            
        
                Rok
            
            
                    2019
                    
                
            
                    Strany
                
            
                        1–9
                
            
                        Sborník
                
            
                    Proceedings of the 6th Conference on the Engineering of Computer Based Systems
                
            
                    Řada
                
            
                    ECBS '19
                
            
                    Konference
                
            
                    6th Conference on the Engineering of Computer Based Systems
                
            
                    ISBN
                
            
                    978-1-4503-7636-5
                
            
                    Vydavatel
                
            
                    Association for Computing Machinery
                
            
                    Místo
                
            
                    New York
                
            
                    DOI
                
            
                    UT WoS
                
            
                    000525376600018
                
            
                EID Scopus
                
            
                    BibTeX
                
            @inproceedings{BUT159987,
  author="Petr {Matoušek} and Ondřej {Ryšavý} and Matěj {Grégr}",
  title="Security Monitoring of IoT Communication Using Flows",
  booktitle="Proceedings of the 6th Conference on the Engineering of Computer Based Systems",
  year="2019",
  series="ECBS '19",
  pages="1--9",
  publisher="Association for Computing Machinery",
  address="New York",
  doi="10.1145/3352700.3352718",
  isbn="978-1-4503-7636-5",
  url="http://doi.acm.org/10.1145/3352700.3352718"
}
                Soubory
            
        
                Projekty
            
        
        
            
        
    
    
        IRONSTONE - IoT monitoring and forensics, TAČR, Program podpory spolupráce v aplikovaném výzkumu a experimentálním vývoji prostřednictvím společných projektů technologických a inovačních agentur DELTA, TF03000029, zahájení: 2016-11-01, ukončení: 2019-10-31, ukončen
                
Nástroje, metody a technologie ICT pro podporu konceptu smart cities, VUT, Vnitřní projekty VUT, FIT-S-17-3964, zahájení: 2017-03-01, ukončení: 2020-02-29, ukončen
        Nástroje, metody a technologie ICT pro podporu konceptu smart cities, VUT, Vnitřní projekty VUT, FIT-S-17-3964, zahájení: 2017-03-01, ukončení: 2020-02-29, ukončen
                Výzkumné skupiny
            
        
                NES@FIT - Výzkumná skupina počítačové sítě (VZ NES@FIT)
            
        
                Pracoviště
            
        
                Ústav informačních systémů 
                (UIFS)