Ethernet Device Authentication via Physical Layer Fingerprinting
William Suski, Christopher J. Card, Brian Richard Few · 2023
Device authentication is an important element of any strong defense-in-depth strategy for securing cyber-physical, industrial control, and other critical infrastructure systems. However, the current stable of solutions available to perform device authentication are not suitable for deployment on many operational technology networks due to the power and processing limitations of legacy and state-of-the-art Internet-of-Things devices. In this paper, we propose a machine learning method for passively and non-invasively authenticating or fingerprinting Ethernet devices, at the physical layer (PHY), using their transmitted signals. This technique exploits the unique, intrinsic physical features of a device that are created by the operational characteristics of its discrete physical components. These characteristics are imprinted on a device’s communication signal, can be externally monitored to authenticate/authorize registered devices, and can quickly detect the introduction of unknown and/or unauthorized devices. We assess the performance of our proposed technique based on the discrimination power in a device classification scenario.