Reliable Identification of IoT Devices from Passive Network Traffic Analysis: Requirements and Recommendations

Internet of Things (IoT) devices are becoming more widespread in networks and can give malicious actors new vectors to compromise networks. Of particular concern are devices running out-of-date firmware versions with known vulnerabilities. Securing real-world IoT networks therefore relies on knowing...

Full description

Saved in:
Bibliographic Details
Published in2023 IEEE 9th World Forum on Internet of Things (WF-IoT) pp. 1 - 6
Main Authors Andrews, Ashley, Oikonomou, George, Armour, Simon, Thomas, Paul, Cattermole, Thomas
Format Conference Proceeding
LanguageEnglish
Published IEEE 12.10.2023
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:Internet of Things (IoT) devices are becoming more widespread in networks and can give malicious actors new vectors to compromise networks. Of particular concern are devices running out-of-date firmware versions with known vulnerabilities. Securing real-world IoT networks therefore relies on knowing what devices are on a network and knowing what specific firmware versions they are running. At present, though, commercial solutions that include IoT device identification are not reliable at this level of granularity, and the academic literature has largely ignored the problem. In this paper, we highlight the shortcomings present in current IoT device identification and use these observations to develop a set of lab requirements. We then present our own lab setup for providing reliable real-world IoT device identification that meets this set of requirements. Building on this work, we develop a schema for documenting device versions and event histories that accompany network packet traces as metadata.
ISSN:2768-1734
DOI:10.1109/WF-IoT58464.2023.10539470