A novel risk-based access control engine in zero trust architecture for IoT network
摘要
The Internet of Things (IoT) and Wireless Sensor Network (WSN) market has grown recently. Therefore, security issues on IoT Networks are considerably important. This study proposes the zero trust-enabled trust evaluation mechanism that continuously evaluates the trust of neighbor nodes to prevent attackers from endangering the availability and reliability of the overall IoT networks. In zero trust, each node's behavior should be considered to avoid damage to the overall network. This study uses various indicators to evaluate the trust of each interaction behavior, including capability, feature, activity, and data contents. This study evaluates the behaviors through the ability of the interaction node and the expected behavior. The experiment result shows that the proposed method can detect and mitigate the four types of attacks in Routing Protocol for Low-Power and Lossy Network (RPL), and the proposed method has less misjudgment.