arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.11649cs.CRcs.AI

闭环:物联网部署中用于自动化、异常驱动网络撤销的访问控制架构

Closing the Loop: An Access-Control Architecture for Automated, Anomaly-Driven Network Revocation in IoT Deployments

Muhammet Emir Korkmaz, Kemal Bicakci, Yusuf Uzunay

首次发表
浏览论文内容

中文总结 AI 辅助

研究物联网设备网络异常检测后自动执行的问题,提出用标准协议构建访问控制架构,由异常信号驱动,经测试在单设备上效果良好,能可靠触发响应,完成设备逐出和证书撤销,还将探讨多设备泛化。

中文摘要 AI 辅助

基于网络的物联网设备异常检测已成熟,检测准确率高,但多数系统仅发出警报,将自动执行问题留待未来工作或很少有实际网络运行的可编程数据平面。本文提出一种仅使用已部署标准协议的访问控制架构。设备通过带EAP - TLS的IEEE 802.1X认证,RADIUS服务器作为连续策略决策点,可通过授权变更断开请求逐出活跃会话并通过证书撤销永久排除设备。中央上下文访问策略引擎持续接收异常检测器输出并通过受限通道向RADIUS服务器触发响应。该机制由基于先前MUD/SDN设计改编的一类检测器的异常信号驱动。在单个测试设备上,检测器AUC达0.9964,用比参考设计少约43倍训练数据检测所有24种评估攻击场景,警报能可靠触发自动断开然后撤销响应,平均335.8毫秒逐出设备,再用111.5毫秒完成证书撤销。本文将此评估作为闭环架构的演示,而非检测器本身,并讨论多设备泛化作为下一步具体工作。

英文摘要

Network-based anomaly detection for IoT devices has matured to the point of reporting strong detection accuracy, yet most published systems stop at raising an alert and leave the question of automated enforcement to future work or to a programmable data plane that few real networks operate. This paper presents an access-control architecture that closes that loop using only standard, already-deployed protocols. Devices authenticate via IEEE 802.1X with EAP-TLS, and a RADIUS server acts as a continuous policy decision point capable of evicting an active session via a Change-of-Authorization Disconnect-Request and permanently excluding a device through certificate revocation. A central, contextual access policy engine continuously consumes the anomaly detector's output and actuates this response over a narrowly restricted channel to the RADIUS server; the same engine is designed to be extensible to other access types, though this paper evaluates only the network access-control mechanism. This mechanism is driven by an anomaly signal from a one-class detector adapted from a prior MUD/SDN-based design, replacing its per-flow multi-model pipeline with passive traffic capture and a single fused model that combines a cluster-based, a volumetric, and a protocol-signature score. On a single testbed device, the detector reaches an AUC of 0.9964 and detects all 24 evaluated attack scenarios (eight attack types at three intensities) using roughly 43$\times$ less training data than the reference design, and the resulting alerts reliably trigger the automated disconnect-then-revoke response, which we measure to evict a device from the network in 335.8\,ms on average and complete certificate revocation in a further 111.5\,ms. We report this evaluation as a demonstration of the closed-loop architecture rather than of the detector itself, and discuss multi-device generalization as a concrete next step.

发表机构

  • Security Training Consulting Inc.(安全培训咨询公司)
  • Informatics Institute, Istanbul Technical University(信息学院,伊斯坦布尔技术大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑