Real-Time Dynamic Configuration of Firewall Rules for High-Speed IoT Networks

Yu-An Shao, C. Chao
{"title":"Real-Time Dynamic Configuration of Firewall Rules for High-Speed IoT Networks","authors":"Yu-An Shao, C. Chao","doi":"10.1109/ECICE55674.2022.10042899","DOIUrl":null,"url":null,"abstract":"The Internet of Things (IoT) is indispensable to modern society. It has entered the mainstream trend recently owing to its ability to read data and connect systems. IoT network platforms comprise various applications, leading to an influx of heavy and varying network traffic, allowing hackers to launch large-scale network attacks easily. When hackers gain control of an IoT device, they can initiate large-scale botnet attacks even through nonconventional computing devices such as cameras and routers. For example, Dyn, a domain name system provider, experienced large-scale distributed denial-of-service attacks on its IoT devices in 2016, causing companies, such as Twitter and Amazon, to suffer the consequences. Therefore, adapting to large-scale changes in network traffic in real-time is imperative. Firewalls are the foundation of device security. Therefore, when large-scale changes in network traffic occur, it is necessary to ensure the effectiveness of firewalls to reduce the probability of successful attacks. This study proposes a system that can adjust the order of firewall rules in real-time to monitor the traffic in high-speed IoT networks. When the system detects a sudden increase in the number of packets, the firewall rules are reordered and applied immediately to ensure security. Additionally, the original filtering effect of the firewall is maintained without being compromised. The test results indicate that high-speed network firewall performance has improved significantly with no abnormality detected in the filtering effect.","PeriodicalId":282635,"journal":{"name":"2022 IEEE 4th Eurasia Conference on IOT, Communication and Engineering (ECICE)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2022-10-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE 4th Eurasia Conference on IOT, Communication and Engineering (ECICE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ECICE55674.2022.10042899","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The Internet of Things (IoT) is indispensable to modern society. It has entered the mainstream trend recently owing to its ability to read data and connect systems. IoT network platforms comprise various applications, leading to an influx of heavy and varying network traffic, allowing hackers to launch large-scale network attacks easily. When hackers gain control of an IoT device, they can initiate large-scale botnet attacks even through nonconventional computing devices such as cameras and routers. For example, Dyn, a domain name system provider, experienced large-scale distributed denial-of-service attacks on its IoT devices in 2016, causing companies, such as Twitter and Amazon, to suffer the consequences. Therefore, adapting to large-scale changes in network traffic in real-time is imperative. Firewalls are the foundation of device security. Therefore, when large-scale changes in network traffic occur, it is necessary to ensure the effectiveness of firewalls to reduce the probability of successful attacks. This study proposes a system that can adjust the order of firewall rules in real-time to monitor the traffic in high-speed IoT networks. When the system detects a sudden increase in the number of packets, the firewall rules are reordered and applied immediately to ensure security. Additionally, the original filtering effect of the firewall is maintained without being compromised. The test results indicate that high-speed network firewall performance has improved significantly with no abnormality detected in the filtering effect.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
高速物联网防火墙规则的实时动态配置
物联网(IoT)是现代社会不可或缺的一部分。由于它具有读取数据和连接系统的能力,最近进入了主流趋势。物联网网络平台包含各种应用,导致大量不同的网络流量涌入,黑客很容易发动大规模的网络攻击。黑客一旦控制了物联网设备,就可以通过摄像头、路由器等非常规计算设备发动大规模僵尸网络攻击。例如,2016年,域名系统提供商Dyn的物联网设备遭受了大规模的分布式拒绝服务攻击,导致Twitter和亚马逊等公司遭受了后果。因此,实时适应网络流量的大规模变化势在必行。防火墙是设备安全的基础。因此,当网络流量发生大规模变化时,需要保证防火墙的有效性,以降低攻击成功的概率。本研究提出了一种可以实时调整防火墙规则顺序的系统,用于高速物联网网络的流量监控。当系统检测到报文数量突然增加时,会立即重新排序并应用防火墙规则,以保证安全。同时保持了防火墙原有的过滤效果,不影响防火墙原有的过滤效果。测试结果表明,高速网络防火墙的性能有了明显的提高,过滤效果没有发现异常。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
License Plate Recognition Model For Tilt Correction Based on Convolutional Neural Network Quaternion Singular Spectrum Analysis of Pupillary Dynamics for Health Monitoring Trajectory Tracking Control of Autonomous Lawn Mower Based on ANSMC Task Scheduling with Makespan Minimization for Distributed Machine Learning Ensembles Socially Assistive Robots Assisting Older Adults in an Internet and Smart Healthcare Era: A Literature Review
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1