From Source Code to Network Profile: Automated and Traceable MUD Profile Generation for IoT Devices

πŸ“… 2026-09-25
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the limitations of existing traffic-driven Manufacturer Usage Description (MUD) generation methods, which depend on device deployment, struggle to capture rare communication paths, and lack traceability. To overcome these challenges, this work proposes AutoMUD, a tool that pioneers a source-code-driven paradigm for automatically generating accurate, complete, and traceable MUD access policies from IoT firmware source code. The approach integrates static syntax extraction, retrieval-augmented large language model reasoning, and deterministic verification compilation. Its core contribution lies in enabling bidirectional traceability between generated rules and code-level evidence while explicitly documenting exclusion rationales to facilitate manual review. Experimental evaluations on Linux repositories demonstrate that AutoMUD successfully recovers complete communication behaviors, and fault injection tests further validate its capability for error localization and correction.
πŸ“ Abstract
The Manufacturer Usage Description (MUD) standard allows IoT manufacturers to define expected network behaviors in a MUD file. This file can be translated into enforceable access-control policies, restricting compromised devices to operate solely through manufacturer-defined communication patterns. However, practical adoption of MUD depends on profiles that are accurate, complete, and maintainable. Existing approaches use traffic-based automation but require device deployment and prolonged monitoring, capturing only behavior exercised during observation. Rare, failure-triggered, or configuration-dependent communications may remain absent, producing incomplete policies that disrupt legitimate operation and offer limited insight into the software components responsible for each rule. We present AutoMUD, a source-code-driven tool that generates traceable MUD profiles for IoT devices from their firmware and software source code. AutoMUD combines static and syntactic extraction, retrieval-grounded language-model reasoning, and deterministic validation and compilation to recover the communication behavior characterizing an IoT device and translate eligible endpoints into policy rules. By analyzing code-level evidence, AutoMUD exposes rarely exercised and conditional communication paths, links every generated rule to its source-level provenance, and preserves excluded findings with explicit reasons for review. Our evaluation on a Linux-based repository demonstrates that AutoMUD recovers complete communication behavior, consolidates validated behavior into semantic endpoint groups, and generates structurally valid MUD profiles. Through a controlled semantic fault-injection campaign, we demonstrate that AutoMUD enables analysts to detect, localize, explain, and correct propagated errors, recovering policies semantically identical to their clean counterparts.
Problem

Research questions and friction points this paper is trying to address.

Manufacturer Usage Description (MUD)
IoT security
network profile generation
access-control policies
profile traceability
Innovation

Methods, ideas, or system contributions that make the work stand out.

Manufacturer Usage Description (MUD)
Source Code Analysis
IoT Security
Language Model Reasoning
Traceability
πŸ”Ž Similar Papers
No similar papers found.