Can Flow Metadata Based Signatures Generalize for Identifying Attacks on IoT Devices?
Jeffrey A. Adjei, Nur Zincir-Heywood, Malcolm Iain Heywood, Biswajit Nandy, Nabil Seddigh · 2025
In this research, we investigate the impact of four prevalent types of attacks, namely Portscan, Slowloris, Synflood, and Vulnerability Scan, on nine distinct Internet of Things (IoT) devices. These attacks are very common on the IoT eco-systems because they often serve as precursors to more sophisticated attack vectors. By analyzing attack vector traffic characteristics and IoT device responses, we aim to shed light on IoT eco-system vulnerabilities. To achieve this, we utilize and evaluate two feature sets extracted from the network traffic metadata using a flow analyzer, avoiding deep packet inspection. The goal of this research is to evaluate the impact of traffic flow metadata for identifying attacks on IoT devices. We further analyze the two flow feature sets in terms of generalizability of machine learning based attack detection from one IoT network to another. Results show that while generalizability is possible, it also depends on several factors including the characteristics of Iot traffic.