用标准协议实现物联网异常自动断网并吊销证书,响应快至335毫秒。
Closing the Loop: An Access-Control Architecture for Automated, Anomaly-Driven Network Revocation in IoT Deployments

- 通过RADIUS服务器实现异常后自动断开连接并吊销证书,仅依赖现有部署协议。
- 检测器在单设备上AUC达0.9964,用43倍少的数据覆盖24种攻击场景。
- 适合需要快速响应的物联网安全防护场景,尤其适用于已有802.1X网络环境。
基于网络的物联网设备异常检测已具备高准确率,但多数系统仅发出告警,自动化执行仍需未来工作或可编程数据平面支持,而后者在实际网络中应用极少。本文提出一种访问控制架构,利用现有标准协议闭合这一闭环。设备通过IEEE 802.1X与EAP-TLS认证,RADIUS服务器作为持续策略决策点,可通过Change-of-Authorization Disconnect-Request主动踢出会话,并通过证书吊销永久排除设备。一个中心化的上下文感知策略引擎持续接收异常检测器输出,通过受控通道向RADIUS发送指令;该引擎设计可扩展至其他接入类型,本文仅评估网络访问控制机制。该机制基于一类异常检测器,其改进自先前基于MUD/SDN的设计,将原每流多模型流水线替换为被动流量采集与单一融合模型,综合聚类、流量规模与协议特征得分。在单个测试设备上,检测器达到AUC 0.9964,以约43倍更少的训练数据检测全部24种攻击场景(8类攻击,每类3种强度),且告警可稳定触发自动断连再吊销流程。我们测得平均335.8毫秒内完成设备踢出,后续111.5毫秒完成证书吊销。本评估旨在展示闭环架构可行性,而非检测器本身性能,多设备泛化是下一步具体目标。
原文摘要 · Abstract (English)
Network-based anomaly detection for IoT devices has matured to the point of reporting strong detection accuracy, yet most published systems stop at raising an alert and leave the question of automated enforcement to future work or to a programmable data plane that few real networks operate. This paper presents an access-control architecture that closes that loop using only standard, already-deployed protocols. Devices authenticate via IEEE 802.1X with EAP-TLS, and a RADIUS server acts as a continuous policy decision point capable of evicting an active session via a Change-of-Authorization Disconnect-Request and permanently excluding a device through certificate revocation. A central, contextual access policy engine continuously consumes the anomaly detector's output and actuates this response over a narrowly restricted channel to the RADIUS server; the same engine is designed to be extensible to other access types, though this paper evaluates only the network access-control mechanism. This mechanism is driven by an anomaly signal from a one-class detector adapted from a prior MUD/SDN-based design, replacing its per-flow multi-model pipeline with passive traffic capture and a single fused model that combines a cluster-based, a volumetric, and a protocol-signature score. On a single testbed device, the detector reaches an AUC of 0.9964 and detects all 24 evaluated attack scenarios (eight attack types at three intensities) using roughly 43$\times$ less training data than the reference design, and the resulting alerts reliably trigger the automated disconnect-then-revoke response, which we measure to evict a device from the network in 335.8\,ms on average and complete certificate revocation in a further 111.5\,ms. We report this evaluation as a demonstration of the closed-loop architecture rather than of the detector itself, and discuss multi-device generalization as a concrete next step.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。