AutoMUD: Source‑Code‑Driven MUD Profile Generation for IoT
Abstract
IoT device may communicate with malicious endpoints, ports, or services unrelated to its intended function [6]. Restricting each device to the communications required for its legitimate operation can therefore reduce the impact of compromise. The Manufacturer Usage Description (MUD) standard allows manufacturers of Internet of Things (IoT) devices to define in a MUD file the profile of the expected network behavior of their devices. The MUD file can then be translated into enforceable access-control policies, thus restricting compromised devices to operate solely through manufacturer-defined communication patterns. However, the practical adoption of MUD depends on profiles that are accurate, complete, and maintainable. Existing approaches use traffic-based automation to reduce the manual effort to create MUD profiles, but require device deployment and prolonged monitoring, while capturing only behavior exercised during observation. Rare, failuretriggered, or configuration-dependent communications may remain absent, producing incomplete policies that may disrupt legitimate operation and offer limited insight into the software components responsible for each rule. The Manufacturer Usage Description (MUD) standard of the Internet Engineering Task Force (IETF) implements this principle by allowing manufacturers to describe the intended network behavior of a device through a machine-readable MUD profile [16]. A MUD controller can retrieve this profile and translate it into accesscontrol policies, treating undeclared traffic as unauthorized[13, 16, 21]. Despite its potential, MUD adoption today remains limited, especially because producing and maintaining accurate profiles requires detailed knowledge of devices communication behavior [13, 21, 34]. Within large manufacturers of IoT devices, this knowledge may be distributed across firmware, cloud-service, integration, and network teams, making manual profile construction time consuming, error-prone, and difficult to maintain across devices, configurations, and software versions [13, 34]. In this paper, we present AutoMUD, a source-code-driven tool that generates traceable MUD profiles for IoT devices from their firmware and software source code. AutoMUD combines static and syntactic extraction, retrieval-grounded language-model reasoning, and deterministic validation and compilation to recover the communication behavior characterizing an IoT device and translate eligible endpoints into policy rules. By analyzing code-level evidence, AutoMUD exposes even rarely exercised and conditional communication paths, links every generated rule to its source-level provenance, and preserves excluded findings with explicit reasons for review. Our evaluation on a Linux-based repository demonstrates that AutoMUD recovers the complete communication behavior, consolidates the validated behavior into semantic endpoint groups, and generates the expected structurally valid MUD profile. Through a controlled semantic fault-injection campaign, we also demonstrate that AutoMUD enables an analyst to detect, localize, explain, and correct propagated errors, recovering policies semantically identical to their clean counterparts. To date, the only automated solution to this problem is the use of traffic-based tools, such as MudGee [10], which reduce manual effort of MUD profile generating by translating observed communications into MUD rules. However, they require devices to be deployed and monitored for sufficiently long periods to obtain representative traces [9, 11, 20]. Even then, rare, configuration-dependent, updaterelated, or failure-triggered communications may remain unobserved and consequently absent from the generated policy [1, 6, 37]. Such omissions may later disrupt legitimate operation when the profile is enforced. Moreover, if the device is compromised during data collection, its MUD profile could inevitably encode malicious behavior. Furthermore, traffic traces may show that some communications occurred, but they provide limited evidence about the software component, configuration, or execution path that caused it. In this context, manufacturers could significantly benefit from an automated MUD generation approach that can recover the expected network behavior by connecting each communication pattern to inspectable evidence without requiring device deployment.