National Cybersecurity Center of Excellence Mitigating IoT-Based - - PowerPoint PPT Presentation

national cybersecurity center of excellence
SMART_READER_LITE
LIVE PREVIEW

National Cybersecurity Center of Excellence Mitigating IoT-Based - - PowerPoint PPT Presentation

National Cybersecurity Center of Excellence Mitigating IoT-Based DDoS Build 1 Demonstration Presentation April 10, 2019 Challenge There will be 20.4 billion connected IoT devices by 2020 (per Gartner) As IoT devices become more common


slide-1
SLIDE 1

National Cybersecurity Center of Excellence

Mitigating IoT-Based DDoS

Build 1 Demonstration Presentation April 10, 2019

slide-2
SLIDE 2

2 nccoe.nist.gov National Cybersecurity Center of Excellence

Challenge

  • There will be 20.4 billion

connected IoT devices by 2020 (per Gartner)

  • As IoT devices become more

common in homes and businesses, security concerns are also increasing

  • IoT devices represent one of the

largest attack surfaces – Some have minimal security, are unprotected or are difficult to secure

  • DDoS attacks increased by 28%

in 2017 (per Akamai)

  • Recently IoT devices have been

exploited to launch DDoS attacks (e.g. Mirai)

slide-3
SLIDE 3

3 nccoe.nist.gov National Cybersecurity Center of Excellence

Typical Home/Small Business Network (Without MUD)

slide-4
SLIDE 4

Home/Small Business Internet Attacker Manufacturer Server

slide-5
SLIDE 5

Internet Attacker Manufacturer Server Home/Small Business

slide-6
SLIDE 6

Internet Manufacturer Server Attacker Home/Small Business

slide-7
SLIDE 7

Internet Manufacturer Server Attacker Home/Small Business

slide-8
SLIDE 8

Internet Manufacturer Server Attacker Home/Small Business

slide-9
SLIDE 9

Internet Manufacturer Server Attacker Home/Small Business

slide-10
SLIDE 10

Internet Manufacturer Server Attacker Home/Small Business

slide-11
SLIDE 11

Internet Manufacturer Server Attacker Home/Small Business

slide-12
SLIDE 12

Internet Manufacturer Server Attacker Home/Small Business

slide-13
SLIDE 13

Internet Manufacturer Server Attacker Home/Small Business

slide-14
SLIDE 14

14 nccoe.nist.gov National Cybersecurity Center of Excellence

Typical Home/Small Business Network (With MUD)

slide-15
SLIDE 15

Internet Attacker Manufacturer Server Home/Small Business

slide-16
SLIDE 16

Internet Manufacturer Server Attacker Home/Small Business

slide-17
SLIDE 17

Internet Manufacturer Server Attacker Home/Small Business

slide-18
SLIDE 18

Internet Manufacturer Server Attacker Home/Small Business

slide-19
SLIDE 19

Internet Manufacturer Server Attacker Home/Small Business

slide-20
SLIDE 20

20 nccoe.nist.gov National Cybersecurity Center of Excellence

Architecture Overview

slide-21
SLIDE 21

21 nccoe.nist.gov National Cybersecurity Center of Excellence

Logical Architecture

MUD Manager Devices Router or Switch Home or Small Business Network MUD File Server Update Server (2a) MUD URL

(5a) Device traffic filters

(1) MUD URL in DHCP transaction (6) IP Address Update Protocol FreeRadius (2b) MUD URL (5b) Device traffic filters

One Device

(3a) HTTPS get URL (MUD file) (3b) MUD file (4a) HTTPS get URL (Signature file) (4b) Signature file

slide-22
SLIDE 22

22 nccoe.nist.gov National Cybersecurity Center of Excellence

Demonstration

slide-23
SLIDE 23

23 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 1: Connect Device

Devices Router or Switch Home or Small Business Network (1) MUD URL in DHCP transaction

slide-24
SLIDE 24

24 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 1: Connect Device

  • 1. No session on interface

Router or Switch

  • 3. Interface state changed to up

Router or Switch

  • 2. Connect MUD enabled IoT Device

Devices Devices

slide-25
SLIDE 25

25 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 2a/2b: Send MUD URL to MUD Manager

MUD Manager Devices Router or Switch Home or Small Business Network (2a) MUD URL (1) MUD URL in DHCP transaction FreeRadius (2b) MUD URL

One Device

slide-26
SLIDE 26

26 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 2a/2b: Send MUD URL to MUD Manager

  • 1. FreeRadius service receives and passes MUD URL

FreeRadius

slide-27
SLIDE 27

27 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 2b: Send MUD URL to MUD Manager

  • 2. MUD Manager receives MUD enabled IoT Device

information from FreeRadius Service

MUD Manager

slide-28
SLIDE 28

28 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 3/4: Get MUD and Signature File

MUD Manager Devices Router or Switch Home or Small Business Network MUD File Server (2a) MUD URL (1) MUD URL in DHCP transaction FreeRadius (2b) MUD URL

One Device

(3a) HTTPS get URL (MUD file) (3b) MUD file (4a) HTTPS get URL (Signature file) (4b) Signature file

slide-29
SLIDE 29

29 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 3/4: Send MUD URL to MUD Manager

  • 1. MUD Manager receives message
  • 2. Get MUD and Signature file

MUD Manager MUD Manager

  • 3. Verify MUD file

MUD Manager

slide-30
SLIDE 30

30 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 5a: Send Device Traffic Filters

MUD Manager Devices Router or Switch Home or Small Business Network MUD File Server (2a) MUD URL

(5a) Device traffic filters

(1) MUD URL in DHCP transaction FreeRadius (2b) MUD URL

One Device

(3a) HTTPS get URL (MUD file) (3b) MUD file (4a) HTTPS get URL (Signature file) (4b) Signature file

slide-31
SLIDE 31

31 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 5a: Send Device Traffic Filters

  • 1. MUD File parsed and translated to ACL (rules)
  • 2. MUD Manager sends ACL

MUD Manager MUD Manager

slide-32
SLIDE 32

32 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 5a: Send Device Traffic Filters

  • 3. FreeRadius receives ACL from MUD Manager

FreeRadius

slide-33
SLIDE 33

33 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 5b: Send Device Traffic Filters

MUD Manager Devices Router or Switch Home or Small Business Network MUD File Server (2a) MUD URL

(5a) Device traffic filters

(1) MUD URL in DHCP transaction FreeRadius (2b) MUD URL

One Device

(3a) HTTPS get URL (MUD file) (3b) MUD file (4a) HTTPS get URL (Signature file) (4b) Signature file (5b) Device traffic filters

slide-34
SLIDE 34

34 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 5b: Send Device Traffic Filters

  • 1. FreeRadius sends ACL to switch
  • 2. ACL received and configurations applied

FreeRadius Router or Switch

slide-35
SLIDE 35

35 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 6: IP Address Assigned

MUD Manager Devices Router or Switch Home or Small Business Network MUD File Server (2a) MUD URL

(5a) Device traffic filters

(1) MUD URL in DHCP transaction FreeRadius (2b) MUD URL

One Device

(3a) HTTPS get URL (MUD file) (3b) MUD file (4a) HTTPS get URL (Signature file) (4b) Signature file (5b) Device traffic filters (6) IP Address

slide-36
SLIDE 36

36 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 6: IP address assigned

  • 1. IoT Device receives IP address

Devices

slide-37
SLIDE 37

37 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 6: IP address assigned

  • 1. Show access-session
  • 2. Show access-lists

Router or Switch Router or Switch

slide-38
SLIDE 38

38 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 7: Test communication

MUD Manager Devices Router or Switch Home or Small Business Network MUD File Server (2a) MUD URL

(5a) Device traffic filters

(1) MUD URL in DHCP transaction FreeRadius (2b) MUD URL

One Device

(3a) HTTPS get URL (MUD file) (3b) MUD file (4a) HTTPS get URL (Signature file) (4b) Signature file (5b) Device traffic filters (6) IP Address Update Server Update Protocol

slide-39
SLIDE 39

39 nccoe.nist.gov National Cybersecurity Center of Excellence

Step 7: Test communication

  • 1. Test browsing to “Update Server”
  • 2. Test browsing to unapproved server

Devices Devices

slide-40
SLIDE 40

40 nccoe.nist.gov National Cybersecurity Center of Excellence

Next Steps

MUD Manager Devices Router or Switch Home or Small Business Network MUD File Server (2a) MUD URL

(5a) Device traffic filters

(1) MUD URL in DHCP transaction FreeRadius (2b) MUD URL

One Device

(3a) HTTPS get URL (MUD file) (3b) MUD file (4a) HTTPS get URL (Signature file) (4b) Signature file (5b) Device traffic filters (6) IP Address Threat Signaling Threat Signaling Server (w/ Intel Provided data) Update Server Update Protocol

slide-41
SLIDE 41

Questions