Internet of Things (IoT) Device Fingerprinting for Anomaly Detection

Oluwatosin Olajide Falola · 2020

Diverse Internet of Things (IoT) devices are continuously introduced in a variety of environments, e.g., home, industry, military, etc. Unfortunately, these devices can be exploited to perpetrate severe attacks, as shown with the MIRA attack. Mobile network operators need to protect their assets and customers, but they do not have full control on these devices, as they are deployed on the customers' premises. Data generated by IoT devices and collected at the operator's end can be analyzed to learn their behaviours and infer their identities (fingerprints). The latter helps in detecting malicious and faulty devices. This thesis presents IoT security in general, and anomaly detection and fingerprinting in particular. The different architectures and methods used for detecting anomalies in the network and inferring the identity of IoT devices connected will be detailed. More importantly, we propose an efficient solution to fingerprint IoT devices using machine learning algorithms. Precisely, we identify the minimal subset of IoT device features that captures the essence of the device fingerprints. That is, without using the entire data collected from IoT devices, which is huge, a small subset can be used to predict the IoT device fingerprints, with high prediction quality. We validate our solution with a known dataset of IoT network traffic, from which different partitions are created based on different feature subsets. On each partition, selected machine learning algorithms are trained, and the prediction quality of the obtained models are calculated. The obtained results show that using only four features, instead of 17, IoT device fingerprints can be accurately predicted. The prediction quality is measured using precision, recall, and harmonic mean, and the obtained results are 99.10%, 99.00%, and 99.00%, respectively. ii

Read the paper · More papers on PaperTik