IoT System Vulnerability Analysis and Network Hardening with Shortest Attack Trace in a Weighted Attack Graph

May 9, 2023· Yinxin Wan Equal contribution , Xuanli Lin Equal contribution , Abdulhakim Sabur , Alena Chang , Kuai Xu , Guoliang Xue · 1 min read
Best Paper Award
Summary
This paper introduces weighted attack graphs for analyzing IoT vulnerabilities and selecting network protections. It develops a shortest-attack-trace algorithm, proves the network-hardening problem is NP-hard, and provides exact and heuristic solutions. Tests on nine synthetic systems and two smart-home testbeds show fast analysis and near-optimal heuristic hardening.
Type
Publication
Proceedings of the 8th ACM/IEEE Conference on Internet of Things Design and Implementation, 315-326. ACM
Awards
Best Paper Award
IoTDI · 2023
publication

Abstract

In recent years, Internet of Things (IoT) devices have been extensively deployed in edge networks, including smart homes and offices. Despite the exciting opportunities afforded by the advancements in the IoT, it also introduces new attack vectors and vulnerabilities in the system. Existing studies have shown that the attack graph is an effective model for performing system-level analysis of IoT security. In this paper, we study IoT system vulnerability analysis and network hardening. We first extend the concept of attack graph to weighted attack graph and design a novel algorithm for computing a shortest attack trace in a weighted attack graph. We then formulate the network hardening problem. We prove that this problem is NP-hard, and then design an exact algorithm and a heuristic algorithm to solve it. Extensive experiments on 9 synthetic IoT systems and 2 real-world smart home IoT testbeds demonstrate that our shortest attack trace algorithm is robust and fast, and our heuristic network hardening algorithm is efficient in producing near optimal results compared to the exact algorithm.

Best Paper Award Recipient

Yinxin Wan
Authors
Assistant Professor of Computer Science
Yinxin Wan is an assistant professor in the Department of Computer Science at the University of Massachusetts Boston. His research focuses on cybersecurity, secure and trustworthy artificial intelligence, network measurement, the Internet of Things, and quantum networking. He received his PhD in Computer Science from Arizona State University in 2023, advised by Guoliang Xue and Kuai Xu, and his bachelor’s degree in Information Security from the University of Science and Technology of China.
Xuanli Lin
Authors
PhD Student in Computer Science

Xuanli Lin is a fifth-year PhD student in the Computer Science department at Arizona State University, supervised by Dr. Guoliang Xue.

His research interests include network optimization, network security, artificial intelligence, and the Internet of Things.

Kuai Xu
Authors
Professor of Computer Science
Kuai Xu is a professor of computer science in the School of Mathematical and Natural Sciences at Arizona State University. His research covers network security, network measurement and analysis, cloud computing, home networks, and online social networks. He received his PhD in Computer Science from the University of Minnesota in 2006 and his bachelor’s and master’s degrees in Computer Science from Peking University in 1998 and 2001, respectively.
Guoliang Xue
Authors
Professor of Computer Science and Engineering
Guoliang Xue is a professor in Arizona State University’s School of Computing and Augmented Intelligence and an IEEE Fellow. He investigates wireless and quantum networks, network security and privacy, and optimization. He earned his PhD in computer science from the University of Minnesota in 1991. His honors include the IEEE Communications Society’s 2019 William R. Bennett Prize, and he chaired the IEEE INFOCOM Steering Committee from 2020 through 2025.