SINTTRA: Sliding Window Based Temporally Aware Network Traffic Analyzer for IoT Device Fingerprinting
Vibhum Raj Tripathi, Srikant Tangirala, Divakarla Venkata Sasanka, Dheeraj Reddy, Chinmay S Dalal, Barsha Mitra · 2024
In recent years, the growing demand for connected technologies has lead to an exponential surge in the number of IoT devices worldwide. This has resulted in the IoT ecosystems been relentlessly targeted by cyber criminals with the sole aim of compromising the IoT devices. Such compromised devices exhibit abnormal behavior that are manifested in the corresponding network traffic patterns. Anomalous network traffic behavior can be detected with the help of IoT device fingerprinting. Device fingerprinting involves analysis of the network traffic patterns of the IoT devices to create a unique digital blueprint of each of the devices. Such blueprints help to distinguish between normal and abnormal device behaviors, thereby providing indications of possible device compromise and also to detect the presence of a new device. In this paper, we propose an IoT device fingerprinting strategy that uses a sliding window based approach to analyze the characteristics of the network traffic generated by the IoT devices. Our fingerprinting strategy performs packet-level network traffic analysis. However, instead of considering the individual network packets, the proposed sliding window based method aggregates a fixed number of packets to create the device fingerprints. Moreover, the method ensures overlap between successive windows while aggregating the packets to retain the temporal relationships among the different packets of a single IoT device. We name our strategy as SINTTRA, Sliding wINdow based Temporally aware neTwork tRaffic Analyzer. SINTTRA uses supervised machine learning for categorizing the different IoT devices. We have evaluated the efficacy of SINTTRA on network traffic traces collected from our own IoT testbed setup as well as the open-source UNSW IoT dataset. We have also compared the performance of SINTTRA with the flow-based network traffic analysis for device fingerprinting. For both datasets, SINTTRA performs better than the flow-based approach by a margin of 2% to 10% in terms of accuracy, precision, recall and F1-score.