IoT-Proctor: A Secure and Lightweight Device Patching Framework for Mitigating Malware Spread in IoT Networks

被引:15
作者
Aman, Muhammad Naveed [1 ]
Javaid, Uzair [2 ]
Sikdar, Biplab [2 ]
机构
[1] Natl Univ Singapore, Sch Comp, Singapore 117417, Singapore
[2] Natl Univ Singapore, Dept Elect & Comp Engn, Singapore 117576, Singapore
来源
IEEE SYSTEMS JOURNAL | 2022年 / 16卷 / 03期
基金
新加坡国家研究基金会;
关键词
Logic gates; Malware; Security; Physical unclonable function; Protocols; Performance evaluation; Wireless fidelity; Internet of Things (IoT); malware; network security; patching; software attestation; ATTESTATION;
D O I
10.1109/JSYST.2021.3070404
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Traditional malware propagation control schemes do not prevent device-to-device (D2D) malware spread, have high time cost, and may result in low probability of detecting compromised devices. Moreover, the unprecedented scale and heterogeneity of Internet of Things (IoT) devices make these schemes inapplicable to IoT networks. Therefore, to rectify these issues, this article presents a secure patching framework for IoT with different network isolation levels to efficiently mitigate and control malware propagation. It uses remote attestation to detect compromised devices with a high probability and identify the origin of malicious activities. It also proposes virtual patching of devices via physical unclonable functions (PUFs) to contain the malware spread. The isolation levels are based on the susceptible, exposed, infected, and resistant (SEIR) model that act as an access control list to quantify device operation and mitigate D2D malware spread. We present a security analysis based on the access control logic model. A performance evaluation with a comparative analysis is also discussed using the SEIR model. These analyses confirm the reduction in patching time and superior performance of our framework, i.e., with 10% of initially infected devices, IoT-Proctor had a reduction rate of malware five times faster than the existing techniques.
引用
收藏
页码:3468 / 3479
页数:12
相关论文
共 52 条
  • [1] Aman M. N., IEEE SYST J
  • [2] Aman M.N., 2016, P 2 ACM INT WORKSH I, P10, DOI DOI 10.1145/2899007.2899013
  • [3] A Privacy-Preserving and Scalable Authentication Protocol for the Internet of Vehicles
    Aman, Muhammad Naveed
    Javaid, Uzair
    Sikdar, Biplab
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (02) : 1123 - 1139
  • [4] HAtt: Hybrid Remote Attestation for the Internet of Things With High Availability
    Aman, Muhammad Naveed
    Basheer, Mohamed Haroon
    Dash, Siddhant
    Wong, Jun Wen
    Xu, Jia
    Lim, Hoon Wei
    Sikdar, Biplab
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (08) : 7220 - 7233
  • [5] Data Provenance for IoT With Light Weight Authentication and Privacy Preservation
    Aman, Muhammad Naveed
    Basheer, Mohammed Haroon
    Sikdar, Biplab
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (06): : 10441 - 10457
  • [6] Two-Factor Authentication for IoT With Location Information
    Aman, Muhammad Naveed
    Basheer, Mohamed Haroon
    Sikdar, Biplab
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (02): : 3335 - 3351
  • [7] ATT-Auth: A Hybrid Protocol for Industrial IoT Attestation With Authentication
    Aman, Muhammad Naveed
    Sikdar, Biplab
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2018, 5 (06): : 5119 - 5131
  • [8] Low Power Data Integrity in IoT Systems
    Aman, Muhammad Naveed
    Sikdar, Biplab
    Chua, Kee Chaing
    Ali, Anwar
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2018, 5 (04): : 3102 - 3113
  • [9] Aman MN, 2017, 2017 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING, P310, DOI 10.1109/DESEC.2017.8073853
  • [10] [Anonymous], 2011, 6238 RFC