从源代码到网络配置文件:面向物联网设备的自动化且可追溯的 MUD 配置文件生成
From Source Code to Network Profile: Automated and Traceable MUD Profile Generation for IoT Devices
浏览论文内容
中文总结 AI 辅助
本文提出 AutoMUD,一种从物联网设备源代码自动生成可追溯 MUD 配置文件的工具,通过静态提取与语言模型推理恢复完整通信行为,并链接规则到代码出处,实验证明其能生成有效配置并支持错误检测与修正。
中文摘要 AI 辅助
制造商使用说明(MUD)标准允许物联网制造商在 MUD 文件中定义预期的网络行为。该文件可以被转换为可执行的访问控制策略,限制受损设备仅能通过制造商定义的通信模式进行操作。然而,MUD 的实际采用依赖于准确、完整且可维护的配置文件。现有方法使用基于流量的自动化,但需要设备部署和长时间监控,仅捕获观察期间所表现出的行为。罕见、故障触发或配置相关的通信可能仍然缺失,从而产生不完整的策略,干扰合法操作,并且对每条规则所对应的软件组件提供的洞察有限。我们提出了 AutoMUD,一种源代码驱动的工具,可从物联网设备的固件和软件源代码生成可追溯的 MUD 配置文件。AutoMUD 结合了静态与语法提取、基于检索增强的语言模型推理以及确定性验证和编译,以恢复表征物联网设备的通信行为,并将符合条件的端点转换为策略规则。通过分析代码级证据,AutoMUD 揭示了很少执行的和条件性的通信路径,将每条生成的规则链接到其源代码级出处,并保留被排除的发现及其明确原因以供审查。我们在一个基于 Linux 的代码库上的评估表明,AutoMUD 能够恢复完整的通信行为,将验证过的行为整合到语义端点组中,并生成结构有效的 MUD 配置文件。通过受控的语义故障注入实验,我们证明了 AutoMUD 使分析人员能够检测、定位、解释和纠正传播的错误,从而恢复与其干净版本语义相同的策略。
英文摘要
The Manufacturer Usage Description (MUD) standard allows IoT manufacturers to define expected network behaviors in a MUD file. This file can be translated into enforceable access-control policies, restricting compromised devices to operate solely through manufacturer-defined communication patterns. However, practical adoption of MUD depends on profiles that are accurate, complete, and maintainable. Existing approaches use traffic-based automation but require device deployment and prolonged monitoring, capturing only behavior exercised during observation. Rare, failure-triggered, or configuration-dependent communications may remain absent, producing incomplete policies that disrupt legitimate operation and offer limited insight into the software components responsible for each rule. We present AutoMUD, a source-code-driven tool that generates traceable MUD profiles for IoT devices from their firmware and software source code. AutoMUD combines static and syntactic extraction, retrieval-grounded language-model reasoning, and deterministic validation and compilation to recover the communication behavior characterizing an IoT device and translate eligible endpoints into policy rules. By analyzing code-level evidence, AutoMUD exposes rarely exercised and conditional communication paths, links every generated rule to its source-level provenance, and preserves excluded findings with explicit reasons for review. Our evaluation on a Linux-based repository demonstrates that AutoMUD recovers complete communication behavior, consolidates validated behavior into semantic endpoint groups, and generates structurally valid MUD profiles. Through a controlled semantic fault-injection campaign, we demonstrate that AutoMUD enables analysts to detect, localize, explain, and correct propagated errors, recovering policies semantically identical to their clean counterparts.
发表机构
- University of Padua(帕多瓦大学)
- Eindhoven University of Technology(埃因霍温理工大学)
机构由 AI 辅助整理,请以论文原文为准。