Machine Learning for the Detection and Identification of Internet of Things Devices: A Survey

Machine Learning for the Detection and Identification of Internet of Things Devices: A Survey
复制标题

DOI:
10.1109/jiot.2021.3099028
复制
发表时间:
2022-01-01
影响因子:
10.6
通讯作者:
Song, Houbing
Song, Houbing
中科院分区:
计算机科学1区
文献类型:
--
作者:
Liu, Yongxin;Wang, Jian;Song, Houbing

文献摘要

被引文献

相似文献

物联网 (IoT) 正在成为日常生活中不可或缺的一部分,催生了各种新兴服务和应用。然而,恶意物联网设备的存在使物联网面临难以言喻的风险,并带来严重后果。保护物联网安全的第一步是检测恶意物联网设备并识别合法设备。传统方法使用加密机制来验证和验证合法设备的身份。然而,加密协议在许多系统中不可用。同时,当合法设备被利用或加密密钥被泄露时,这些方法的效果就较差。因此,非加密物联网设备识别和恶意设备检测成为保护现有系统的有效解决方案,并将为具有加密协议的系统提供额外的保护。非加密方法需要更多努力,并且尚未得到充分研究。在本文中,我们从被动监视代理或网络运营商的角度对用于识别物联网设备以及检测受损或伪造设备的机器学习技术进行了全面的调查。我们将物联网设备识别和检测分为四类:1)设备特定模式识别; 2)基于深度学习的设备识别; 3)无监督设备识别; 4)异常设备检测。同时,我们为此讨论了各种与机器学习相关的支持技术。这些支持技术包括学习算法、网络流量轨迹和无线信号的特征工程、增量学习和异常检测。
The Internet of Things (IoT) is becoming an indispensable part of everyday life, enabling a variety of emerging services and applications. However, the presence of rogue IoT devices has exposed the IoT to untold risks with severe consequences. The first step in securing the IoT is detecting rogue IoT devices and identifying legitimate ones. Conventional approaches use cryptographic mechanisms to authenticate and verify legitimate devices' identities. However, cryptographic protocols are not available in many systems. Meanwhile, these methods are less effective when legitimate devices can be exploited or encryption keys are disclosed. Therefore, noncryptographic IoT-device identification and rogue device detection become efficient solutions to secure existing systems and will provide additional protection to systems with cryptographic protocols. Noncryptographic approaches require more effort and are not yet adequately investigated. In this article, we provide a comprehensive survey on machine learning technologies for the identification of IoT devices along with the detection of compromised or falsified ones from the viewpoint of passive surveillance agents or network operators. We classify the IoT-device identification and detection into four categories: 1) device-specific pattern recognition; 2) deep learning-enabled device identification; 3) unsupervised device identification; and 4) abnormal device detection. Meanwhile, we discuss various ML-related enabling technologies for this purpose. These enabling technologies include learning algorithms, feature engineering on network traffic traces and wireless signals, incremental learning, and abnormality detection.