错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Viz \(^4\) NetSec: Visualizing Dynamic Network Security Configurations of Everyday Interconnected Objects in Home Networks

  • Noëlle Rakotondravony,
  • Henrich C. Pöhls,
  • Jan Pfeifer,
  • Lane Harrison

摘要

Controlling the communication of devices within a network by compartmentalization or segmentation is one of many techniques to protect and improve the overall security of networked systems. Meaningful instrumentation of network segmentation requires having an overview of the devices that participate in the network; only then users can seize control of what devices are allowed to do in terms of communication. In this work, we consider a minimized set of network security controls (i.e. allow connections, allow in-bound-only, allow out-bound-only) that can be implemented using modern routers with built-in firewall or even Software Defined Networking (SDN) capabilities. We present Viz \(^4\) NetSec, a node-link diagram for visualizing typical home user network scenarios. The visualization is integrated in an existing smart home control software and provides an interactive interface through which a smart home user can find, dynamically interact with, and isolate devices by setting SDN flow rules. The aspect of dynamicity in this paper is important as we envision that everyday users would reasonably need interactions to trigger configuration changes that directly change the network’s or the device’s behavior because this enabled users to configure network rules in a trial and error or ‘gamified’ fashion. Thus, dynamicity empowers adapting security decisions (mostly in the sense of privacy) to their ever-changing everyday digital lives. We conclude this work with an evaluation of the proposed network visualization, discussing how home network users can use the available functionalities in Viz \(^4\) NetSec to perform the isolation of devices within the network as the most simple security related task.