Network Traffic Fingerprinting for IoT Device Identification Using Machine Learning
Jamal Haydar, Linda Kanaan, Ali Mokdad, Ali Beydoun · 2025
The increasing deployment of Internet of Things (IoT) devices introduces significant security challenges, particularly in identifying and managing devices within large-scale networks. This paper proposes an efficient machine learning-based method for passive identification of IoT devices through network traffic analysis. Using a combination of two publicly available datasets, we construct a diverse dataset comprising 42 different IoT devices - more than any previously reported work in the literature. Using only header-level features and no payload inspection, we employ the ReliefF algorithm to select the most relevant 19 features per packet and aggregate 10 packets to form unique device fingerprints. We evaluated the performance of various classification models, including Support Vector Machines (SVM), Multi-Layer Perceptrons (MLP), and Random Forests. The Random Forest classifier achieves the highest accuracy of 96.04% while offering low training time and robustness, outperforming state-of-the-art systems such as IoT Sentinel, which achieved 82% accuracy on a smaller dataset. Our system achieves high accuracy in distinguishing between devices of the same model and the vendor, demonstrating robust performance in detailed device classification. The results show that using only header data is an effective and non-intrusive method for identifying IoT devices at scale. Future work will focus on improving the system by incorporating traffic morphing techniques and evaluating its performance in real-time under varying network conditions.