IoT Device Fingerprinting Using Byte Histograms
Jack Nunnelee, Alex Howe, Philip Rahal, Mauricio Papa · 2025
Device fingerprinting in the Internet of Things (IoT) is a promising security technique which allows organizations to leverage unique device characteristics in order to classify future unknown devices and validate outputs from known devices. This paper introduces two novel contributions: a device fingerprinting method using byte histograms and a classification technique based on the Jensen-Shannon divergence score. Byte histograms represent the true behavior of a device by capturing byte-level data from its network packets, offering enhanced explainability for similarities observed between devices. Unlike traditional feature-based fingerprints, byte histograms are device and protocol-agnostic, making them highly generalizable for use in different environments. Furthermore, byte histograms simplify the network restructuring process, ensuring seamless adaptability. We demonstrate the robust fingerprinting capabilities and accurate classification of the proposed byte histogram-based method by classifying both known and unknown IoT devices. Three state-of-the-art machine learning algorithms are used for comparison to validate the proposed approach. This work demonstrates the efficacy of byte histogram-based fingerprints and highlights the advantages of byte-level granularity for IoT network security and device classification applications.