Manufacturer Usage Description (RFC 8520)


Generated Profiles

GitHub: [repo]/network_captures/mud_gen

MUD Profiles

MUD files whitelist the nature of network traffic that a device should transmit/receive.

(e.g. Transmit IPv4 tcp/8890 to (DNS)

Traffic that does not match the MUD are discarded (or allowed but flagged). Mitigates unexpected ports/hosts - but ineffective against (e.g.) C2 payloads

IoT Research Team @ UNSW EE&T has done some research

Not really adopted?

Only used in Cisco catalyst switches