Securing IoT Devices using Geographic and Continuous Login Blocking: A Honeypot Study

Fredrik Heiding, Mohammad-Ali Omer, Andreas Wallström, Robert Lagerström

Abstract

IoT (Internet of Things) devices have grown exponentially in the last years, both in the sheer number of devices and concerning areas of applications being introduced. Together with this rapid development we are faced with an increased need for IoT Security. Devices that have previously been analogue, such as refrigerators, door locks, and cars are now turning digital and are exposed to the threats posed by an Internet connection. This paper investigates how two existing security features (geographic IP Blocking with GeoIP and rate-limited connections with fail2ban) can be used to enhance the security of IoT devices. We analyze the success of each method by comparing units with and without the security features, collecting and comparing data about the received attacks for both kinds. The result shows that the GeoIP security feature can reduce attacks by roughly 93% and fail2ban by up to 99%. Further work in the field is encouraged to validate our findings, create better GeoIP tools, and to better understand the potential of the security techniques at a larger scale. The security features are implemented in aws instances made to simulate IoT devices, and measured with honeypots and IDSs (Intrusion Detection Systems) that collect data from the received attacks. The research is made as a fundamental work to later be extended by implementing the security features in more devices, such as single board computers that will simulate IoT devies even more accurately.

Download


Paper Citation


in Harvard Style

Heiding F., Omer M., Wallström A. and Lagerström R. (2020). Securing IoT Devices using Geographic and Continuous Login Blocking: A Honeypot Study.In Proceedings of the 6th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-399-5, pages 424-431. DOI: 10.5220/0008954704240431


in Bibtex Style

@conference{icissp20,
author={Fredrik Heiding and Mohammad-Ali Omer and Andreas Wallström and Robert Lagerström},
title={Securing IoT Devices using Geographic and Continuous Login Blocking: A Honeypot Study},
booktitle={Proceedings of the 6th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,},
year={2020},
pages={424-431},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0008954704240431},
isbn={978-989-758-399-5},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 6th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,
TI - Securing IoT Devices using Geographic and Continuous Login Blocking: A Honeypot Study
SN - 978-989-758-399-5
AU - Heiding F.
AU - Omer M.
AU - Wallström A.
AU - Lagerström R.
PY - 2020
SP - 424
EP - 431
DO - 10.5220/0008954704240431