MUD (Manufacturer Usage Description, RFC 8520)
Что такое MUD (Manufacturer Usage Description, RFC 8520)?
MUD (Manufacturer Usage Description, RFC 8520)An IETF standard for IoT devices to publish a machine-readable description of their intended network behavior, which routers and switches can use to automatically constrain the device to its expected communication patterns.
Manufacturer Usage Description (MUD, RFC 8520), published by the IETF in 2019, is a framework for IoT devices to advertise to the network exactly what communication they need. A MUD-aware device sends a MUD URL during DHCP, LLDP, or 802.1X — pointing to a small JSON file (the 'MUD file') hosted by the manufacturer. The MUD file describes intended endpoints (controller cloud services, NTP servers, etc.), allowed protocols, and allowed peer roles in a structured policy language. A MUD-aware switch, router, or NAC translates that description into per-device ACLs or microsegmentation rules, denying everything outside the manufacturer's declared behavior. The intent is to make 'one camera-vendor's botnet' impossible — a compromised IP camera cannot scan or pivot to other internal hosts because the network refuses anything outside the device's declared profile. NIST SP 1800-15 published a reference architecture and Cisco, Aruba, and several IoT-security vendors implement MUD or MUD-like profiles. Adoption is limited because it requires manufacturer participation, but MUD remains the most concrete IETF answer to the 2016-Mirai-class IoT worm threat.
● Примеры
- 01
A MUD-aware switch receives a MUD URL from a new IP camera, fetches its profile, and applies an ACL that allows traffic only to the vendor's cloud endpoint and NTP — blocking all peer-to-peer attempts.
- 02
NIST SP 1800-15 demonstrates MUD enforcement constraining a compromised IoT device so it cannot participate in a Mirai-style scanning botnet.
● Частые вопросы
Что такое MUD (Manufacturer Usage Description, RFC 8520)?
An IETF standard for IoT devices to publish a machine-readable description of their intended network behavior, which routers and switches can use to automatically constrain the device to its expected communication patterns. Относится к категории OT / ICS / IoT в кибербезопасности.
Что означает MUD (Manufacturer Usage Description, RFC 8520)?
An IETF standard for IoT devices to publish a machine-readable description of their intended network behavior, which routers and switches can use to automatically constrain the device to its expected communication patterns.
Как работает MUD (Manufacturer Usage Description, RFC 8520)?
Manufacturer Usage Description (MUD, RFC 8520), published by the IETF in 2019, is a framework for IoT devices to advertise to the network exactly what communication they need. A MUD-aware device sends a MUD URL during DHCP, LLDP, or 802.1X — pointing to a small JSON file (the 'MUD file') hosted by the manufacturer. The MUD file describes intended endpoints (controller cloud services, NTP servers, etc.), allowed protocols, and allowed peer roles in a structured policy language. A MUD-aware switch, router, or NAC translates that description into per-device ACLs or microsegmentation rules, denying everything outside the manufacturer's declared behavior. The intent is to make 'one camera-vendor's botnet' impossible — a compromised IP camera cannot scan or pivot to other internal hosts because the network refuses anything outside the device's declared profile. NIST SP 1800-15 published a reference architecture and Cisco, Aruba, and several IoT-security vendors implement MUD or MUD-like profiles. Adoption is limited because it requires manufacturer participation, but MUD remains the most concrete IETF answer to the 2016-Mirai-class IoT worm threat.
Как защититься от MUD (Manufacturer Usage Description, RFC 8520)?
Защита от MUD (Manufacturer Usage Description, RFC 8520) обычно сочетает технические меры и операционные практики, как описано в определении выше.
Какие есть другие названия MUD (Manufacturer Usage Description, RFC 8520)?
Распространённые альтернативные названия: Manufacturer Usage Description, RFC 8520 MUD.
● Связанные термины
- ot-iot№ 615
Безопасность IoT
Дисциплина защиты устройств, шлюзов, сетей и облачных сервисов Интернета вещей с учётом их массовости, ограниченных ресурсов и длительного жизненного цикла.
- ot-iot№ 614
IoT-ботнет
Сеть скомпрометированных IoT-устройств, удалённо управляемая для проведения DDoS, credential stuffing, мошенничества с кликами и криптомайнинга.
- ot-iot№ 758
Ботнет Mirai
Семейство IoT-ВПО, появившееся в 2016 году. Привлекает маршрутизаторы, камеры и DVR через заводские пароли; участвовало в DDoS на Dyn, обрушившем значительную часть интернета в США.
- network-security№ 805
Network Access Control (NAC)
Набор политик и технологий, которые аутентифицируют устройства и пользователей перед предоставлением сетевого доступа и непрерывно контролируют их состояние.
- network-security№ 752
Микросегментация
Тонкая форма сегментации, при которой allow-list политики применяются между отдельными нагрузками или приложениями, обычно средствами хоста или гипервизора.
- network-security№ 809
Сегментация сети
Практика разделения сети на несколько зон с контролируемым трафиком между ними для сдерживания взломов и реализации принципа наименьших привилегий.