通过设备长期使用网络服务的宏观模式,实现轻量级、可解释的物联网设备识别。
From Flows to Functions: Macroscopic Behavioral Fingerprinting of IoT Devices via Network Services
- 基于设备长时间使用的网络服务(如TCP/80)构建宏观指纹
- 在1.5年约1000万条流数据上验证,识别准确率高且稳定
- 适合需要可解释性与低计算开销的物联网安全管理场景
在网络安全管理中,识别摄像头、打印机、语音助手等物联网(IoT)设备至关重要。现有方法多依赖机器学习对短时流量单元(包或流)的细粒度特征进行分析,但存在计算开销大、对测量误差敏感、结果不可解释等问题。本文提出一种宏观、轻量且可解释的设备行为指纹方法,聚焦设备长期使用的网络服务(如TCP/80、UDP/53)。研究发现,不同类型的IoT设备在服务使用模式上具有稳定且可区分的特征。我们定义了服务级指纹概念,并提出可配置粒度的表示方法;通过实验采集13类消费级IoT设备在实验室环境中的流量,共约1000万条IPFIX流记录,持续1.5年,验证了该指纹的收敛性和重复性;最终在封闭集与开放集场景下均验证了其有效性。
原文摘要 · Abstract (English)
Identifying devices such as cameras, printers, voice assistants, or health monitoring sensors, collectively known as the Internet of Things (IoT), within a network is a critical operational task, particularly to manage the cyber risks they introduce. While behavioral fingerprinting based on network traffic analysis has shown promise, most existing approaches rely on machine learning (ML) techniques applied to fine-grained features of short-lived traffic units (packets and/or flows). These methods tend to be computationally expensive, sensitive to traffic measurement errors, and often produce opaque inferences. In this paper, we propose a macroscopic, lightweight, and explainable alternative to behavioral fingerprinting focusing on the network services (e.g., TCP/80, UDP/53) that IoT devices use to perform their intended functions over extended periods. Our contributions are threefold. (1) We demonstrate that IoT devices exhibit stable and distinguishable patterns in their use of network services over a period of time. We formalize the notion of service-level fingerprints and derive a generalized method to represent network behaviors using a configurable granularity parameter. (2) We develop a procedure to extract service-level fingerprints, apply it to traffic from 13 consumer IoT device types in a lab testbed, and evaluate the resulting representations in terms of their convergence and recurrence properties. (3) We validate the efficacy of service-level fingerprints for device identification in closed-set and open-set scenarios. Our findings are based on a large dataset comprising about 10 million IPFIX flow records collected over a 1.5-year period.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。