Towards Classifying Devices on the Internet Using Artificial Intelligence

Artūrs Lavrenovs, Roman Graf, Kimmo Heinaaro · 2020

Hundreds of millions of devices are directly reachable by anyone on the Internet. Security researchers and malicious actors are highly interested in ICS, IoT, and building automation and networking devices that can be compromised to negatively affect either a specific person or organization or a whole country at once. The current approach for determining a class of individual device is to conduct a manual investigation or apply static rules to large sets of devices, which is timeconsuming and ineffective. We are proposing to utilize neural networks for automated classification.Many devices have a generic web interface supporting HTTP protocol. We have investigated which features of the HTTP responses from these devices are meaningful for training the neural network model and enabling classification of devices. We have trained neural network models and assessed their accuracy to be 87%. We are analysing the classified sets of the whole Internet scans consisting of tens of millions of devices and comparing them between the years 2018 and 2019 to identify the changes. This kind of all-encompassing view might reveal positive and negative trends that are happening to specific classes of devices, which might be correlated with real-world events, e.g. new policies issued by governments.

Read the paper · More papers on PaperTik