As IoT devices become more widely deployed, unauthorized activities such as data exfiltration and malware injection are increasing. However, their fixed functionality, limited resources, and physical exposure make traditional signature-based and user-...
As IoT devices become more widely deployed, unauthorized activities such as data exfiltration and malware injection are increasing. However, their fixed functionality, limited resources, and physical exposure make traditional signature-based and user-dependent whitelist methods unsuitable. This paper proposes an eBPF-based automated whitelisting system that generates policies from normal behavior during development and enforces them in the kernel during operation. Experimental results demonstrate that the proposed approach effectively prevents unauthorized executions and network connections with low overhead, making it suitable for IoT environments.