You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 1800-15 Securing Small-Business and Home Internet of Things (IoT) Devices: Mitigating Network-Based Attacks Using Manufacturer Usage Description (MUD) Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: May 2021 Author(s) Donna Dodson (NIST) , Douglas Montgomery (NIST) , W. Polk (NIST) , Mudumbai Ranganathan (NIST) , Murugiah Souppaya (NIST) , Steve Johnson (CableLabs) , Ashwini Kadam (CableLabs) , Craig Pratt (CableLabs) , Darshak Thakore (CableLabs) , Mark Walker (CableLabs) , Eliot Lear (Cisco) , Brian Weis (Cisco) , William Barker (Dakota Consulting) , Dean Coclin (DigiCert) , Avesta Hojjati (DigiCert) , Clint Wilson (DigiCert) , Tim Jones (ForeScout) , Adnan Baykal (Global Cyber Alliance) , Drew Cohen (MasterPeace Solutions) , Kevin Yeich (MasterPeace Solutions) , Yemi Fashina (MITRE) , Parisa Grayeli (MITRE) , Joshua Harrington (MITRE) , Joshua Klosterman (MITRE) , Blaine Mulugeta (MITRE) , Susan Symington (MITRE) , Jaideep Singh (Molex) Abstract The goal of the Internet Engineering Task Force’s Manufacturer Usage Description (MUD) specification is for Internet of Things (IoT) devices to behave as the devices’ manufacturers intended. MUD provides a standard way for manufacturers to indicate the network communications that a device requires to perform its intended function. When MUD is used, the network will automatically permit the IoT device to send and receive only the traffic it requires to perform as intended, and the network will prohibit all other communication with the device, thereby increasing the device’s resilience to network-based attacks. In this project, the NCCoE demonstrated the ability to ensure that when an IoT device connects to a home or small-business network, MUD can automatically permit the device to send and receive only the traffic it requires to perform its intended function. This NIST Cybersecurity Practice Guide explains how MUD protocols and tools can reduce the vulnerability of IoT devices to botnets and other network-based threats as well as reduce the potential for harm from exploited IoT devices. It also shows IoT device developers and manufacturers, network equipment developers and manufacturers, and service providers who employ MUD-capable components how to integrate and use MUD to satisfy IoT users’ security requirements. The goal of the Internet Engineering Task Force’s Manufacturer Usage Description (MUD) specification is for Internet of Things (IoT) devices to behave as the devices’ manufacturers intended. MUD provides a standard way for manufacturers to indicate the network communications that a device requires... See full abstract The goal of the Internet Engineering Task Force’s Manufacturer Usage Description (MUD) specification is for Internet of Things (IoT) devices to behave as the devices’ manufacturers intended. MUD provides a standard way for manufacturers to indicate the network communications that a device requires to perform its intended function. When MUD is used, the network will automatically permit the IoT device to send and receive only the traffic it requires to perform as intended, and the network will prohibit all other communication with the device, thereby increasing the device’s resilience to network-based attacks. In this project, the NCCoE demonstrated the ability to ensure that when an IoT device connects to a home or small-business network, MUD can automatically permit the device to send and receive only the traffic it requires to perform its intended function. This NIST Cybersecurity Practice Guide explains how MUD protocols and tools can reduce the vulnerability of IoT devices to botnets and other network-based threats as well as reduce the potential for harm from exploited IoT devices. It also shows IoT device developers and manufacturers, network equipment developers and manufacturers, and service providers who employ MUD-capable components how to integrate and use MUD to satisfy IoT users’ security requirements. Hide full abstract Keywords access control ; bootstrapping ; botnets ; firewall rules ; flow rules ; Internet of Things (IoT) ; Manufacturer Usage Description (MUD) ; network segmentation ; onboarding ; router ; server ; software update server ; threat signaling ; Wi-Fi Easy Connect Control Families Access Control ; System and Communications Protection Documentation Publication: https://doi.org/10.6028/NIST.SP.1800-15 Download URL Supplemental Material: SP 1800-15 files Project homepage Related NIST Publications: Project Description Document History: 04/24/19: SP 1800-15 (Draft) 11/21/19: SP 1800-15 (Draft) 09/16/20: SP 1800-15 (Draft) 05/26/21: SP 1800-15 (Final) Topics Security and Privacy configuration management , controls , identity & access management , security automation , threats Technologies hardware , networks Applications cybersecurity framework , Internet of Things , small & medium business Laws and Regulations Executive Order 13800 HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov