Manufacturer Usage Description (RFC 8520)

2022-07-19

Generated Profiles

GitHub: [repo]/network_captures/mud_gen


MUD Profiles

MUD files whitelist the nature of network traffic that a device should transmit/receive.

(e.g. Transmit IPv4 tcp/8890 to (DNS) example.com)

Traffic that does not match the MUD are discarded (or allowed but flagged). Mitigates unexpected ports/hosts - but ineffective against (e.g.) C2 payloads

IoT Research Team @ UNSW EE&T has done some research


Not really adopted?

https://www.nccoe.nist.gov/mud-related-resources

Only used in Cisco catalyst switches