arXiv:2606.12793cs.CRcs.IR2026-06

用设备行为语义识别物联网设备,更稳定可靠。

Semantic Identification of IoT Devices from Behavioral Primitives

  • 从设备策略文件提取行为语义,构建可区分的特征表示。
  • 在行为变化时,语义匹配仍能保持识别能力,优于精确匹配。
  • 适合安全监控、设备管理等需要稳定识别的场景。

准确识别物联网设备对安全管理和策略执行至关重要。现有方法通常基于数据包或流量记录学习设备指纹,但这些低层通信模式易受部署环境、软件版本和用户行为影响。本文研究利用制造商使用描述(MUD)文件进行设备识别。MUD文件通过访问控制条目(ACE)描述设备行为,每个ACE包含协议、端点、方向和端口等语义信息,构成行为基元。我们基于28个公开MUD文件中的1,023个ACE实例,构建了基于紧凑行为文本的ACE级语义表示,并分析其几何特性。结果表明,该表示比全文件嵌入更能保留设备间行为差异,且经白化校准后仍有效。在受控运行时变化下评估发现:当与标准MUD重叠度高时,精确匹配表现良好,但重叠稀疏或消失时迅速失效;而语义匹配在各种条件下仍保留有效识别证据。进一步在超过80万条真实IoT流量上验证,精确重叠仍是稳定情况下的最强信号,但在观察初期,语义匹配能更早锁定正确设备,常将其置于最高候选列表中,且在稀疏重叠场景下依然有效。

原文摘要 · Abstract (English)

Accurate identification of IoT devices is important for security management and policy enforcement. Existing approaches typically learn device signatures from packets or flow records. These methods operate on low-level communication observations whose traffic patterns may vary across deployments, software versions, and user interactions. This paper studies device identification using Manufacturer Usage Description (MUD) profiles. MUD profiles describe device behavior using Access Control Entries (ACEs), where each ACE represents a behavioral primitive consisting of protocol, endpoint, direction, and port semantics derived from device communication policy. Our contributions are threefold. First, using 28 publicly available MUD profiles containing 1,023 ACE instances, we construct ACE-level semantic representations from compact behavioral text and analyze their geometric properties. ACE-level representations preserve device-level behavioral distinctions more effectively than whole-profile embeddings and remain effective after whitening calibration. Second, we evaluate semantic ACE matching under controlled runtime variations, including unseen ACEs, drifted hostnames, and partial runtime observation. Exact ACE matching performs well when the overlap with the canonical MUD profile remains high, but degrades sharply when the overlap becomes sparse or disappears. In contrast, semantic ACE matching preserves useful identification evidence across these conditions. Third, we evaluate the same approach on real IoT traffic traces comprising more than 800,000 observed flows. Exact overlap remains the strongest signal when stable overlap exists, while semantic ACE matching provides stronger identification evidence during the early stages of observation, frequently retains the correct device among the highest-ranked candidates, and remains effective under sparse-overlap runtime traffic.

物联网安全设备识别行为分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。