Blocking without breaking: identification and mitigation of
non-essential IoT traffic
non-essential IoT traffic
File(s) 2105.05162v1.pdf (2.36 MB)
Working paper
Author(s)
Type
Working Paper
Abstract
Despite the prevalence of Internet of Things (IoT) devices, there is little
information about the purpose and risks of the Internet traffic these devices
generate, and consumers have limited options for controlling those risks. A key
open question is whether one can mitigate these risks by automatically blocking
some of the Internet connections from IoT devices, without rendering the
devices inoperable. In this paper, we address this question by developing a
rigorous methodology that relies on automated IoT-device experimentation to
reveal which network connections (and the information they expose) are
essential, and which are not. We further develop strategies to automatically
classify network traffic destinations as either required (i.e., their traffic
is essential for devices to work properly) or not, hence allowing firewall
rules to block traffic sent to non-required destinations without breaking the
functionality of the device. We find that indeed 16 among the 31 devices we
tested have at least one blockable non-required destination, with the maximum
number of blockable destinations for a device being 11. We further analyze the
destination of network traffic and find that all third parties observed in our
experiments are blockable, while first and support parties are neither
uniformly required or non-required. Finally, we demonstrate the limitations of
existing blocklists on IoT traffic, propose a set of guidelines for
automatically limiting non-essential IoT traffic, and we develop a prototype
system that implements these guidelines.
information about the purpose and risks of the Internet traffic these devices
generate, and consumers have limited options for controlling those risks. A key
open question is whether one can mitigate these risks by automatically blocking
some of the Internet connections from IoT devices, without rendering the
devices inoperable. In this paper, we address this question by developing a
rigorous methodology that relies on automated IoT-device experimentation to
reveal which network connections (and the information they expose) are
essential, and which are not. We further develop strategies to automatically
classify network traffic destinations as either required (i.e., their traffic
is essential for devices to work properly) or not, hence allowing firewall
rules to block traffic sent to non-required destinations without breaking the
functionality of the device. We find that indeed 16 among the 31 devices we
tested have at least one blockable non-required destination, with the maximum
number of blockable destinations for a device being 11. We further analyze the
destination of network traffic and find that all third parties observed in our
experiments are blockable, while first and support parties are neither
uniformly required or non-required. Finally, we demonstrate the limitations of
existing blocklists on IoT traffic, propose a set of guidelines for
automatically limiting non-essential IoT traffic, and we develop a prototype
system that implements these guidelines.
Date Issued
2021-05-11
Citation
2021
Publisher
arXiv
Copyright Statement
© 2021 The Author(s)
Sponsor
Engineering & Physical Science Research Council (E
Identifier
http://arxiv.org/abs/2105.05162v1
Grant Number
RGS128099 (EP/R03351X/1)
Subjects
cs.NI
cs.NI
Publication Status
Published
