A Haystack Full of Needles: Scalable Detection of IoT Devices in the Wild

A Haystack Full of Needles: Scalable Detection of IoT Devices in the Wild
复制标题

DOI:
10.1145/3419394.3423650
复制
发表时间:
2020-09
期刊:
Proceedings of the ACM Internet Measurement Conference
影响因子:
--
通讯作者:
Said Jawad Saidi;A. Mandalari;Roman Kolcun;H. Haddadi;Daniel J. Dubois;D. Choffnes;Georgios Smaragdakis;A. Feldmann
Said Jawad Saidi;A. Mandalari;Roman Kolcun;H. Haddadi;Daniel J. Dubois;D. Choffnes;Georgios Smaragdakis;A. Feldmann
中科院分区:
其他
文献类型:
--
作者:
Said Jawad Saidi;A. Mandalari;Roman Kolcun;H. Haddadi;Daniel J. Dubois;D. Choffnes;Georgios Smaragdakis;A. Feldmann

文献摘要

被引文献

相似文献

消费者物联网(IoT)设备非常受欢迎,为用户提供丰富多样的功能,从语音助手到家用电器。这些功能通常会带来重大的隐私和安全风险,最近值得注意的是,大规模的全球协同攻击扰乱了大型服务提供商。因此,解决这些风险的重要第一步是了解物联网设备在网络中的位置。虽然存在一些有限的解决方案,但一个关键问题是,只能看到采样流统计数据的互联网服务提供商是否可以进行设备发现。特别是,对于ISP来说,高效和有效地跟踪和跟踪数百万用户部署的物联网设备的活动是一项挑战-所有这些都是通过采样网络数据进行的。在本文中,我们开发并评估了一种可扩展的方法,以准确地检测和监控用户线路上的物联网设备,这些设备具有有限的高采样数据。我们的研究结果表明,数百万个物联网设备可以在几个小时内检测和识别,无论是在主要的ISP还是IXP,使用被动的,稀疏采样的网络流报头。我们的方法能够检测超过77%的物联网制造商的设备,包括智能扬声器等流行设备。虽然我们的方法对于提供网络分析是有效的,但它也突出了重要的隐私后果。
Consumer Internet of Things (IoT) devices are extremely popular, providing users with rich and diverse functionalities, from voice assistants to home appliances. These functionalities often come with significant privacy and security risks, with notable recent large-scale coordinated global attacks disrupting large service providers. Thus, an important first step to address these risks is to know what IoT devices are where in a network. While some limited solutions exist, a key question is whether device discovery can be done by Internet service providers that only see sampled flow statistics. In particular, it is challenging for an ISP to efficiently and effectively track and trace activity from IoT devices deployed by its millions of subscribers---all with sampled network data. In this paper, we develop and evaluate a scalable methodology to accurately detect and monitor IoT devices at subscriber lines with limited, highly sampled data in-the-wild. Our findings indicate that millions of IoT devices are detectable and identifiable within hours, both at a major ISP as well as an IXP, using passive, sparsely sampled network flow headers. Our methodology is able to detect devices from more than 77% of the studied IoT manufacturers, including popular devices such as smart speakers. While our methodology is effective for providing network analytics, it also highlights significant privacy consequences.