arXiv:2512.13709cs.CRcs.LG2025-12被引 1

用机器学习分析网络流量,识别物联网设备类型和行为。

Smart Surveillance: Identifying IoT Device Behaviours using ML-Powered Traffic Analysis

  • 通过监测设备与网络间的流量,结合随机森林等模型分类。
  • 随机森林准确率达91%,能识别多数设备类型与动作。
  • 适合安全团队用于外部监控物联网异常行为。

近年来物联网(IoT)设备数量激增,带来显著安全挑战。通过网络流量分析精准识别设备类型及其行为,对防范潜在威胁至关重要。本研究构建包含NPAT路由器及多种物联网设备(如智能摄像头、控制中枢、家用电器、电源控制器、流媒体设备)的测试环境,采用随机森林(RF)、多层感知机(MLP)和K近邻(KNN)等机器学习方法进行设备类型与行为分类。实验表明,该方法可行,其中随机森林分类准确率最高达91%,多层感知机最低为56%。所有设备类别均被成功识别,但部分安全摄像头相关动作存在识别困难,凸显该方法的潜力与局限。

原文摘要 · Abstract (English)

The proliferation of Internet of Things (IoT) devices has grown exponentially in recent years, introducing significant security challenges. Accurate identification of the types of IoT devices and their associated actions through network traffic analysis is essential to mitigate potential threats. By monitoring and analysing packet flows between IoT devices and connected networks, anomalous or malicious behaviours can be detected. Existing research focuses primarily on device identification within local networks using methods such as protocol fingerprinting and wireless frequency scanning. However, these approaches are limited in their ability to monitor or classify IoT devices externally. To address this gap, we investigate the use of machine learning (ML) techniques, specifically Random Forest (RF), Multilayer Perceptron (MLP), and K-Nearest Neighbours (KNN), in conjunction with targeted network traffic monitoring to classify IoT device types and their actions. We constructed a testbed comprising an NPAT-enabled router and a diverse set of IoT devices, including smart cameras, controller hubs, home appliances, power controllers, and streaming devices. Experimental results demonstrate that IoT device and action recognition is feasible using our proposed ML-driven approach, with the RF classifier achieving the highest accuracy of 91%, while the MLP recorded the lowest accuracy at 56%. Notably, all device categories were successfully classified except for certain actions associated with security cameras, underscoring both the potential and the limitations of the proposed method.

物联网安全机器学习流量分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。