{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T03:45:47Z","timestamp":1784259947105,"version":"3.55.0"},"reference-count":64,"publisher":"Association for Computing Machinery (ACM)","issue":"1-2","license":[{"start":{"date-parts":[[2022,6,30]],"date-time":"2022-06-30T00:00:00Z","timestamp":1656547200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100004482","name":"Kuwait University, Research","doi-asserted-by":"crossref","award":["RQ02\/19"],"award-info":[{"award-number":["RQ02\/19"]}],"id":[{"id":"10.13039\/501100004482","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Auton. Adapt. Syst."],"published-print":{"date-parts":[[2022,6,30]]},"abstract":"<jats:p>Remote exploitation attacks use software vulnerabilities to penetrate through a network of Internet of Things (IoT) devices. This work addresses defending against remote exploitation attacks on vulnerable IoT devices. As an attack mitigation strategy, we assume it is not possible to fix all the vulnerabilities and propose to diversify the open-source software used to manage IoT devices. Our approach is to deploy dynamic cloud-based virtual machine proxies for physical IoT devices. Our architecture leverages virtual machine proxies with diverse software configurations to mitigate vulnerable and static software configurations on physical devices. We develop an algorithm for selecting new configurations based on network anomaly detection signals to learn vulnerable software configurations on IoT devices, automatically shifting towards more secure configurations. Cloud-based proxy machines mediate requests between application clients and vulnerable IoT devices, facilitating a dynamic diversification system. We report on simulation experiments to evaluate the dynamic system. Two models of powerful adversaries are introduced and simulated against the diversified defense strategy. Our experiments show that a dynamically diversified IoT architecture can be invulnerable to large classes of attacks that would succeed against a static architecture.<\/jats:p>","DOI":"10.1145\/3547350","type":"journal-article","created":{"date-parts":[[2022,7,11]],"date-time":"2022-07-11T11:21:23Z","timestamp":1657538483000},"page":"1-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Dynamic System Diversification for Securing Cloud-based IoT Subnetworks"],"prefix":"10.1145","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7738-5864","authenticated-orcid":false,"given":"Hussain","family":"Almohri","sequence":"first","affiliation":[{"name":"Department of Computer Science, Kuwait University, Kuwait"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2009-107X","authenticated-orcid":false,"given":"Layne","family":"Watson","sequence":"additional","affiliation":[{"name":"Departments of Mathematics, Computer Science, and Aeroespace and Ocean Engineering, Virginia Polytechnic Institute &amp; State University, Kuwait"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7988-8943","authenticated-orcid":false,"given":"David","family":"Evans","sequence":"additional","affiliation":[{"name":"Department Computer Science, University of Virginia, Kuwait"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3627-0793","authenticated-orcid":false,"given":"Stephen","family":"Billups","sequence":"additional","affiliation":[{"name":"Department Mathematical and Statistical Sciences, University of Colorado Denver, Kuwait"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,9,7]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/Cybermatics_2018.2018.00278"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/1168918.1168860"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2994777"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2012.153"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00093"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOMW.2013.6970748"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2914223"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2019.00029"},{"key":"e_1_3_1_10_2","unstructured":"Edoardo Barbieri. 2021. Internet of Things and Ubuntu: 2021 Highlights. (December 2021). Retrieved from https:\/\/ubuntu.com\/blog\/iot-and-ubuntu-2021."},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2535929"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/323647.323636"},{"key":"e_1_3_1_13_2","unstructured":"Joseph Birr-Pixton. 2022. Rustls - a Modern TLS Library. (2022). Retrieved from https:\/\/docs.rs\/rustls."},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2874095"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-61176-1_28"},{"key":"e_1_3_1_16_2","unstructured":"Matt Caswell. 2018. Using TLS1.3 With OpenSSL. (Feb. 2018). Retrieved from https:\/\/www.openssl.org\/blog\/blog\/2018\/02\/08\/tlsv1.3\/."},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277329"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3333501"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3333501"},{"key":"e_1_3_1_20_2","first-page":"147","volume-title":"Proceedings of the 2018 USENIX Annual Technical Conference","author":"Celik Z. Berkay","year":"2018","unstructured":"Z. Berkay Celik, Patrick McDaniel, and Gang Tan. 2018. Soteria: Automated IoT safety and security analysis. In Proceedings of the 2018 USENIX Annual Technical Conference. USENIX, Berkeley, CA,147\u2013158."},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23326"},{"key":"e_1_3_1_22_2","unstructured":"Haotian Chi Qiang Zeng Xiaojiang Du and Lannan Luo. 2019. PFirewall: Semantics-Aware Customizable Data Flow Control for Home Automation Systems. (2019). arXiv:1910.07987. Retrieved from https:\/\/arxiv.org\/abs\/1910.07987."},{"key":"e_1_3_1_23_2","first-page":"1","volume-title":"Proceedings of the 15th Conference on USENIX Security Symposium\u2014Volume 15.","author":"Cox Benjamin","year":"2006","unstructured":"Benjamin Cox, David Evans, Adrian Filipi, Jonathan Rowanhill, Wei Hu, Jack Davidson, John Knight, Anh Nguyen-Tuong, and Jason Hiser. 2006. N-variant systems: A secretless framework for security through diversity. In Proceedings of the 15th Conference on USENIX Security Symposium\u2014Volume 15.USENIX Association, 1 pages."},{"key":"e_1_3_1_24_2","unstructured":"National Vulnerability Database. 2021. CVE-2021-21410 Detail. (June 2021). Retrieved from https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-21410."},{"key":"e_1_3_1_25_2","unstructured":"National Vulnerability Database. 2021. CVE-2021-35393 Detail. (August 2021). Retrieved from https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-35393."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2905846"},{"key":"e_1_3_1_27_2","unstructured":"Thai Duong. 2018. Introducing the Tink Cryptographic Software Library. (August 2018). Retrieved from https:\/\/security.googleblog.com\/2018\/08\/introducing-tink-cryptographic-software.html."},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.14722\/diss.2020.23001"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2882794"},{"key":"e_1_3_1_30_2","first-page":"4223","volume-title":"Proceedings of the 30th USENIX Security Symposium.","author":"Fu Chenglong","year":"2021","unstructured":"Chenglong Fu, Qiang Zeng, and Xiaojiang Du. 2021. HAWatcher: Semantics-aware anomaly detection for appified smart homes. In Proceedings of the 30th USENIX Security Symposium.USENIX Association, Berkeley, CA,4223\u20134240. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/fu-chenglong."},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2011.5958251"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/2602087.2602116"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2903342"},{"key":"e_1_3_1_34_2","first-page":"11","volume-title":"Proceedings of the 2010 USENIX Conference on USENIX Annual Technical Conference.","author":"Hunt Patrick","year":"2010","unstructured":"Patrick Hunt, Mahadev Konar, Flavio P. Junqueira, and Benjamin Reed. 2010. ZooKeeper: Wait-free coordination for internet-scale systems. In Proceedings of the 2010 USENIX Conference on USENIX Annual Technical Conference.USENIX Association, 11."},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/1853919.1853929"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2874398"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1988.8097"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2013.6699037"},{"key":"e_1_3_1_39_2","unstructured":"Ori Karliner. 2018. FreeRTOS TCP\/IP Stack Vulnerabilities \u2013 The Details. (Dec. 2018). Retrieved from https:\/\/blog.zimperium.com\/freertos-tcpip-stack-vulnerabilities-details\/."},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/2500468.2500473"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2013.2269541"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/TC.1968.5008877"},{"key":"e_1_3_1_43_2","unstructured":"Shebu Varghese Kuriakose. 2021. Secure OTA Updates for Cortex-M Devices with FreeRTOS. (July 2021). Retrieved from https:\/\/www.freertos.org\/2021\/07\/secure-ota-updates-for-cortex-m-devices-with-freertos.html."},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/FTCSH.1995.532621"},{"key":"e_1_3_1_45_2","unstructured":"Nikos Mavrogiannopoulos. 2018. GnuTLS and TLS 1.3. (May 2018). Retrieved from https:\/\/nikmav.blogspot.com\/2018\/05\/gnutls-and-tls-13.html."},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.2017.1800100"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3131365.3131369"},{"key":"e_1_3_1_48_2","unstructured":"Roberto Minerva Abyi Biru and Domenico Rotondi. 2015. Towards a Definition of the Internet of Things (IoT). (2015). Retrieved from https:\/\/iot.ieee.org\/definition.html. IEEE Internet Initiative."},{"key":"e_1_3_1_49_2","unstructured":"National Vulnerability Database. 2020. CVE-2020-11896 Detail. Retrieved on July 26 2022 https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-11896."},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/GCWkshps45667.2019.9024539"},{"key":"e_1_3_1_51_2","unstructured":"Phil Neray. 2020. Azure Defender for IoT: Agentless Security for OT. (September 2020). Retrieved from https:\/\/techcommunity.microsoft.com\/t5\/microsoft-defender-for-iot-blog\/azure-defender-for-iot-agentless-security-for-ot\/ba-p\/1698679."},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/3281411.3281440"},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2019.00080"},{"key":"e_1_3_1_54_2","unstructured":"Dan Noal. 2019. Support for Secure Elements in FreeRTOS. (Oct. 2019). Retrieved from https:\/\/aws.amazon.com\/blogs\/iot\/support-for-secure-elements-in-freertos\/."},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2879679"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF00138693"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3140649.3140656"},{"key":"e_1_3_1_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.13"},{"key":"e_1_3_1_59_2","unstructured":"Eric Tucker. 2021. US Seizes 2 Domain Names Used in Cyberespionage Campaign. (June 2021). Retrieved from https:\/\/www.washingtonpost.com\/politics\/us-seizes-2-domain-names-used-in-cyberespionage-campaign\/2021\/06\/01\/9c72cb2c-c316-11eb-89a4-b7ae22aa193e_story.html."},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11212-1_28"},{"key":"e_1_3_1_61_2","first-page":"543","volume-title":"Proceedings of the 12th USENIX Symposium on Networked Systems Design and Implementation.","author":"Wu Zhe","year":"2015","unstructured":"Zhe Wu, Curtis Yu, and Harsha V. Madhyastha. 2015. CosTLO: Cost-effective redundancy for lower latency variance on cloud storage services. In Proceedings of the 12th USENIX Symposium on Networked Systems Design and Implementation.USENIX Association, Oakland, CA, 543\u2013557. Retrieved from https:\/\/www.usenix.org\/conference\/nsdi15\/technical-sessions\/presentation\/wu."},{"key":"e_1_3_1_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2018.2825478"},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/2834050.2834095"},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2993587"},{"key":"e_1_3_1_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2516916"}],"container-title":["ACM Transactions on Autonomous and Adaptive Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3547350","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3547350","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:02:56Z","timestamp":1750186976000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3547350"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,30]]},"references-count":64,"journal-issue":{"issue":"1-2","published-print":{"date-parts":[[2022,6,30]]}},"alternative-id":["10.1145\/3547350"],"URL":"https:\/\/doi.org\/10.1145\/3547350","relation":{},"ISSN":["1556-4665","1556-4703"],"issn-type":[{"value":"1556-4665","type":"print"},{"value":"1556-4703","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,30]]},"assertion":[{"value":"2021-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-05-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-09-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}