Extending a Smart Home firewall with complex interactions and network pattern detection
Files
Gallez_20972000_Zhang_31912301_2025.pdf
Open access - Adobe PDF
- 1.54 MB
Details
- Supervisors
- Faculty
- Degree label
- Abstract
- In the rapidly expanding field of the Internet of Things (IoT), the security of connected devices has become a critical challenge due to their diverse communication patterns and complex device interactions within smart home environments. Traditional security solutions such as Manufacturer Usage Description (MUD) profiles cannot capture the interactions and contextual dependencies that characterize modern IoT device communications. This master's thesis is based on an existing Smart Home Firewall that solves most issues with MUD. We are introducing two firewall enhancements: the Network Activity Period feature, which enables time-based access control using an intuitive cron-like syntax with duration specifications, and the Patterns Loop functionality, which supports cyclical communication patterns in IoT device interactions. Performance evaluations demonstrate that both features maintain very low processing overheads. To address the existing profile creation challenge in the firewall, we developed the Smart Firewall Pattern Detector, a comprehensive tool offering both command-line and web interfaces for automated pattern discovery from network traffic captures. The tool is designed to analyze PCAP files, automatically detecting communication patterns, suggesting device interactions, and giving suggestions for firewall profiles, which can alleviate the burden of manual profile creation for end users. Evaluation using public IoT datasets and controlled experiments shows that our tool successfully identifies most of legitimate device communication patterns while providing meaningful interaction suggestions for complex multi-device scenarios. Though we have to emphasize that our tool has limits as there is no perfect solution for creating a full profile from traces for now.