MICRO-SEGMENTATION OF IOT NETWORKS IN THE ZERO TRUST ARCHITECTURE
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1336Keywords:
Zero Trust architecture, micro-segmentation, Internet of Things, spectral clustering, access policy, lateral movement, attack surface, network graph modelAbstract
The scaling of Internet of Things (IoT) infrastructures is accompanied by redundant network connectivity that expands the attack surface and enables lateral movement of an adversary after a single node has been compromised. The article proposes an automated hybrid method for micro-segmentation of IoT networks that implements the principles of the Zero Trust architecture by combining spectral clustering of the network graph with heuristic role-based pruning. The network is modeled as a directed graph with hierarchical device levels (edge, aggregation, gateway, cloud) and node criticality coefficients. A synthetic topology generator with a controlled noise level has been developed; it reproduces the functional core of connections and a stochastic entropy component using preferential attachment and zone affinity mechanisms. To quantify the quality of segmentation, a system of weighted metrics has been formed: weighted Attack Surface Reduction (wASR), weighted Lateral Movement Index (wLMI), False Block Rate (FBR), and Policy Compression Ratio (PCR). The experimental study covers three network scales (about 30, 330, and 950 devices) with noise intensity from 0 to 5; the results are averaged over three runs, and 95% confidence intervals are provided. It is shown that for large-scale networks the method reduces the weighted lateral movement index by 72–88% depending on the noise level, while keeping the false block rate within 1.5–3% at noise levels up to 3, which preserves the functional integrity of the system. The synthesized access policies are compact (policy compression ratio of 0.71–0.83 under high noise), which reduces the operational complexity of security administration. The limitations of the method for small networks, where graph sparsity increases sensitivity to noise, are identified. Prospects for further research are outlined: dynamic re-segmentation in real time, automatic selection of the number of segments, and validation on real IoT traffic datasets.
Downloads
References
MITRE. (2025). Lateral movement, tactic TA0008 (Enterprise). MITRE ATT&CK. Retrieved August 16, 2026, from https://attack.mitre.org/tactics/TA0008/
Osman, A., Wasicek, A., Köpsell, S., & Strufe, T. (2020). Transparent microsegmentation in smart home IoT networks. In 3rd USENIX Workshop on Hot Topics in Edge Computing (HotEdge ’20). USENIX Association. https://www.usenix.org/conference/hotedge20/presentation/osman
Saltzer, J. H., & Schroeder, M. D. (1975). The protection of information in computer systems. Proceedings of the IEEE, 63(9), 1278-1308. https://doi.org/10.1109/PROC.1975.9939
Smiliotopoulos, C., Kambourakis, G., & Kolias, C. (2024). Detecting lateral movement: A systematic survey. Heliyon, 10(4), e26317. https://doi.org/10.1016/j.heliyon.2024.e26317
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Makhdoom, I., Abolhasan, M., Lipman, J., Liu, R. P., & Ni, W. (2019). Anatomy of threats to the Internet of Things. IEEE Communications Surveys & Tutorials, 21(2), 1636-1675. https://doi.org/10.1109/COMST.2018.2874978
Samaniego, M., & Deters, R. (2018). Zero-trust hierarchical management in IoT. In 2018 IEEE International Congress on Internet of Things (ICIOT) (pp. 88-95). https://doi.org/10.1109/ICIOT.2018.00019
Arifeen, M., Petrovski, A., & Petrovski, S. (2021). Automated microsegmentation for lateral movement prevention in Industrial Internet of Things (IIoT). In 2021 14th International Conference on Security of Information and Networks (SIN) (pp. 1-6). https://doi.org/10.1109/SIN54109.2021.9699232
Lear, E., Droms, R., & Romascanu, D. (2019). Manufacturer usage description specification (RFC 8520). RFC Editor. https://doi.org/10.17487/RFC8520
Krishnan, P., Jain, K., Buyya, R., Vijayakumar, P., Nayyar, A., Bilal, M., & Song, H. (2022). MUD-based behavioral profiling security framework for software-defined IoT networks. IEEE Internet of Things Journal, 9(9), 6611-6622. https://doi.org/10.1109/JIOT.2021.3113577
Miettinen, M., Marchal, S., Hafeez, I., Asokan, N., Sadeghi, A.-R., & Tarkoma, S. (2017). IoT SENTINEL: Automated device-type identification for security enforcement in IoT. In 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS) (pp. 2177-2184). https://doi.org/10.1109/ICDCS.2017.283
von Luxburg, U. (2007). A tutorial on spectral clustering. Statistics and Computing, 17(4), 395-416. https://doi.org/10.1007/s11222-007-9033-z
Jouyban, M., & Hosseini, S. (2025). Complex network security using community structure and dynamical analysis: Spectral clustering and VEIP-WQU model. Applied Network Science, 10, 24. https://doi.org/10.1007/s41109-025-00717-8
Manadhata, P. K., & Wing, J. M. (2011). An attack surface metric. IEEE Transactions on Software Engineering, 37(3), 371-386. https://doi.org/10.1109/TSE.2010.60
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Іван Нєдєльніцев, Іван Антіпов

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.