Identifying IoT devices and events based on packet length from encrypted traffic

Identifying IoT devices and events based on packet length from encrypted traffic
复制标题

DOI:
10.1016/j.comcom.2019.05.012
复制
发表时间:
2019-08-15
影响因子:
6
通讯作者:
Campelo, Divanilson R.
Campelo, Divanilson R.
中科院分区:
计算机科学3区
文献类型:
--
作者:
Pinheiro, Antonio J.;Bezerra, Jeandro de M.;Campelo, Divanilson R.

文献摘要

被引文献

相似文献

最近,机器学习算法已被用于识别物联网(IoT)设备和事件。然而,现有的提案可能会检查数据包有效载荷,这会给物联网用户的隐私带来风险,并且可能会使用几个功能,从而增加流量分类的计算复杂性。此外,现有技术还可以使用复杂的机制来提取业务特性,包括创建包含来自传输控制协议(TCP)会话的数据的向量。本文提出了一种解决方案,该解决方案使用来自加密流量的数据包长度统计信息来表征智能家居场景中物联网设备和事件的行为。该解决方案仅使用统计平均值、标准差和在一秒窗口内传输的字节数,这些数据可以从加密流量中提取,从而不需要使用TCP向量。该解决方案识别物联网设备和事件,例如智能助理的语音命令,并区分物联网和非物联网设备。用于表征物联网设备和事件的解决方案使用来自两个真实世界测试平台和五个分类器的流量进行评估。评估包括算法k-最近邻(k-NN),决策树,随机森林,支持向量机(SVM)和多数投票,一些最流行的流量分类算法。结果表明,随机森林算法在设备识别方面可以达到高达96%的准确率,在区分物联网和非物联网设备方面可以达到99%的准确率,在识别物联网设备事件方面可以达到99%的准确率。假设检验用于验证所获得的结果。此外,结果表明,在设备识别中评估的五种分类器中,决策树的延迟最低,其次是k-NN,随机森林,SVM和多数投票。
Recently, machine learning algorithms have been used to identify Internet of Things (IoT) devices and events. However, existing proposals may inspect the packet payload, what creates risks to IoT users' privacy, and may use several features, increasing the computational complexity for traffic classification. In addition, existing techniques may also use complex mechanisms for extracting traffic characteristics, including the creation of vectors containing data from the Transmission Control Protocol (TCP) sessions. This paper proposes a solution that uses packet length statistics from encrypted traffic to characterize the behavior of IoT devices and events in a smart home scenario. The solution uses only the statistical mean, the standard deviation and the number of bytes transmitted over a one-second window, which can be extracted from the encrypted traffic, making the use of TCP vectors unnecessary. The solution identifies IoT devices and events, such as voice commands to smart assistants, and also distinguishes between IoT and non-IoT devices. The solution to characterize IoT devices and events is evaluated with traffic from two real-world testbeds and five classifiers. The evaluation included the algorithms k-Nearest Neighbors (k-NN), Decision Tree, Random Forest, Support Vector Machine (SVM) and Majority Voting, some of the most popular algorithms for traffic classification. The results show that the Random Forest algorithm can achieve up to 96% of accuracy in the identification of devices, 99% of precision in distinguishing between IoT and non-IoT devices and 99% of accuracy in the identification of IoT device events. Hypothesis testing is used to validate the obtained results. Also, the results show that the Decision Tree presented the lowest latency among the five classifiers evaluated in the identification of the devices, followed by k-NN, Random Forest, SVM and Majority Voting.