Mitigating threats in IoT network using device isolation

dc.contributorAalto-yliopistofi
dc.contributorAalto Universityen
dc.contributor.advisorMarchal, Samuel
dc.contributor.authorThapa, Manish
dc.contributor.schoolPerustieteiden korkeakoulufi
dc.contributor.supervisorN., Asokan
dc.date.accessioned2018-04-03T13:24:39Z
dc.date.available2018-04-03T13:24:39Z
dc.date.issued2018-03-19
dc.description.abstractIn recent years, the proliferation of the Internet of Things (IoT) is seen across various sectors. There is a sharp inclination towards using IoT devices in both home and office premises. Many traditional manufacturers are enhancing their traditional appliances into IoT devices. With the myriad of devices in the market, there also exist vulnerable devices which can be exploited by adversaries. Several security solutions are trying to address different areas of security such as network security, privacy, threat detection, etc. IoT Sentinel is one such novel system that can identify device types based on their pattern of communication. IoT Sentinel proposes several isolation levels that can be used to control the traffic of devices identified as vulnerable. IoT Sentinel uses a Software-defined Networking (SDN) component for controlling the traffic flow for devices and isolating them. In this thesis, we develop a solution to extend IoT Sentinel for device isolation, which is not dependent on SDN. The goal is to build a generic and deployable solution for network segmentation and device isolation that is suitable for home networks. The system divides the network into isolated subnets and places new devices into appropriate subnets. Communication between the subnets is controlled using a firewall thereby isolating them. We dynamically configure a DHCP server to place (lease IP address) new IoT devices identified by IoT Sentinel into appropriate subnets based on their level of vulnerability. Using our solution, we can confine vulnerable devices. Thus, the solution minimizes the damage that could be caused by vulnerable devices present in a network. Finally, we evaluate the developed solution for its security requirement of device isolation. We also present the performance evaluation of our solution based on time-delay and throughput analysis. We observe that our solution adds an acceptable delay to the existing IoT Sentinel processes. We also observe that the system throughput is not significantly affected by firewall rules in a home network scenario.en
dc.format.extent73
dc.format.mimetypeapplication/pdfen
dc.identifier.urihttps://aaltodoc.aalto.fi/handle/123456789/30519
dc.identifier.urnURN:NBN:fi:aalto-201804031983
dc.language.isoenen
dc.programmeMaster's Programme in Computer, Communication and Information Sciencesfi
dc.programme.majorMobile Computing, Services and Securityfi
dc.programme.mcodeSCI3045fi
dc.subject.keywordIoTen
dc.subject.keywordIoT sentinelen
dc.subject.keywordnetwork segmentationen
dc.subject.keyworddevice isolationen
dc.titleMitigating threats in IoT network using device isolationen
dc.typeG2 Pro gradu, diplomityöfi
dc.type.ontasotMaster's thesisen
dc.type.ontasotDiplomityöfi
local.aalto.electroniconlyyes
local.aalto.openaccessyes

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
master_Thapa_Manish_2018.pdf
Size:
2.65 MB
Format:
Adobe Portable Document Format