Fingerprinting Edge and Cloud Services in IoT

Fingerprinting Edge and Cloud Services in IoT
复制标题

DOI:
10.1109/sadfe51007.2020.00011
复制
发表时间:
2020-05
期刊:
2020 13th International Conference on Systematic Approaches to Digital Forensic Engineering (SADFE)
影响因子:
--
通讯作者:
DongInn Kim;Vafa Andalibi;L. J. Camp
DongInn Kim;Vafa Andalibi;L. J. Camp
中科院分区:
其他
文献类型:
--
作者:
DongInn Kim;Vafa Andalibi;L. J. Camp

文献摘要

相似文献

如今,物联网(IoT)设备、Web浏览器、电话甚至汽车都可能被采集指纹以进行跟踪,并且它们的连接通过恶意实体路由或路由到恶意实体。当物联网设备与远程服务交互时,该服务的完整性或身份验证得不到保证。物联网和其他边缘设备可能会受到中间人(MiTM)攻击,物联网设备试图连接到远程服务。使用网络钓鱼或域欺骗来说服用户接受与潜在恶意的不熟悉设备的连接也很简单。这些风险可以通过利用网络边缘上有关连接路径和目的地的信息来减轻。在这项工作中,我们采样数据包,然后使用数据包分析和本地历史,以确定危险或可疑的连接。与其他机器学习和大数据方法相比,使用本地数据可以在不损失隐私的情况下进行风险检测。
Today, Internet of Things (IoT) devices, web browsers, phones, and even cars may be fingerprinted for tracking, and their connections routed through or to malicious entities. When IoT devices interact with a remote service, the integrity or authentication of that service is not guaranteed. IoT and other edge devices could be subject to man-in-the-middle (MiTM) attacks, with IoT devices attempting to connect to remote services. It is also straight-forward to use phishing or pharming to convince a user to accept a connection to a potentially malicious unfamiliar device. These risks could be mitigated by leveraging information on the edge of the network about the path to and destination of a connection. In this work we sample packets, then use packet analysis and local history to identify risky or suspicious connections. In contrast to other machine learning and big data approaches, the use of local data enables risk detection without loss of privacy.