Comparing Two-stage Clustering Methods for Traffic Pattern Analysis in IoT Device Identification
Mizuki Asano, Takumi Miyoshi, Taku Yamazaki · 2024
In anticipation of environments where Internet of things (IoT) is extensively utilized, various methods for understanding and managing the behavior of IoT devices based on traffic analysis have been proposed to tackle security issues such as the difficulties in replacing devices, updating their firmware, and comprehending their behavior. We have previously studied an IoT traffic analysis and device identification in smart home environments with applying two-stage clustering. This method realizes extracting time-series characteristics of IoT traffic based on unsupervised machine learning, k-means clustering, and identifying 21 IoT devices with a high accuracy. Nevertheless, we have not yet examined whether k-means clustering is appropriate to the two-stage clustering for IoT traffic analysis and device identification. In this paper, we investigate various clustering methods for two-stage clustering and then compare and discuss the characteristics of the methods for IoT traffic analysis and device identification. The results confirm that the k-means clustering or Ward’s method is more suitable for the performance of feature extraction and the computational loads.