loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Fredrik Heiding ; Mohammad-Ali Omer ; Andreas Wallström and Robert Lagerström

Affiliation: Division of Network and Systems Engineering, KTH Royal Institute of Technology, Stockholm, Sweden

Keyword(s): IoT, GeoIP, Fail2ban, Honeypot, Cowrie, p0f, Conpot, Snort, Suricata, Geographic Blocking.

Abstract: IoT (Internet of Things) devices have grown exponentially in the last years, both in the sheer number of devices and concerning areas of applications being introduced. Together with this rapid development we are faced with an increased need for IoT Security. Devices that have previously been analogue, such as refrigerators, door locks, and cars are now turning digital and are exposed to the threats posed by an Internet connection. This paper investigates how two existing security features (geographic IP Blocking with GeoIP and rate-limited connections with fail2ban) can be used to enhance the security of IoT devices. We analyze the success of each method by comparing units with and without the security features, collecting and comparing data about the received attacks for both kinds. The result shows that the GeoIP security feature can reduce attacks by roughly 93% and fail2ban by up to 99%. Further work in the field is encouraged to validate our findings, create better GeoIP tools, and to better understand the potential of the security techniques at a larger scale. The security features are implemented in aws instances made to simulate IoT devices, and measured with honeypots and IDSs (Intrusion Detection Systems) that collect data from the received attacks. The research is made as a fundamental work to later be extended by implementing the security features in more devices, such as single board computers that will simulate IoT devies even more accurately. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 13.58.112.1

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Heiding, F.; Omer, M.; Wallström, A. and Lagerström, R. (2020). Securing IoT Devices using Geographic and Continuous Login Blocking: A Honeypot Study. In Proceedings of the 6th International Conference on Information Systems Security and Privacy - ICISSP; ISBN 978-989-758-399-5; ISSN 2184-4356, SciTePress, pages 424-431. DOI: 10.5220/0008954704240431

@conference{icissp20,
author={Fredrik Heiding. and Mohammad{-}Ali Omer. and Andreas Wallström. and Robert Lagerström.},
title={Securing IoT Devices using Geographic and Continuous Login Blocking: A Honeypot Study},
booktitle={Proceedings of the 6th International Conference on Information Systems Security and Privacy - ICISSP},
year={2020},
pages={424-431},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0008954704240431},
isbn={978-989-758-399-5},
issn={2184-4356},
}

TY - CONF

JO - Proceedings of the 6th International Conference on Information Systems Security and Privacy - ICISSP
TI - Securing IoT Devices using Geographic and Continuous Login Blocking: A Honeypot Study
SN - 978-989-758-399-5
IS - 2184-4356
AU - Heiding, F.
AU - Omer, M.
AU - Wallström, A.
AU - Lagerström, R.
PY - 2020
SP - 424
EP - 431
DO - 10.5220/0008954704240431
PB - SciTePress