首页> 外文会议>IEEE European Symposium on Security and Privacy >IoTFinder: Efficient Large-Scale Identification of IoT Devices via Passive DNS Traffic Analysis
【24h】

IoTFinder: Efficient Large-Scale Identification of IoT Devices via Passive DNS Traffic Analysis

机译:IoTFinder:通过被动DNS流量分析有效地大规模识别IoT设备

获取原文

摘要

Being able to enumerate potentially vulnerable IoT devices across the Internet is important, because it allows for assessing global Internet risks and enables network operators to check the hygiene of their own networks. To this end, in this paper we propose IoTFinder, a system for efficient, large-scale passive identification of IoT devices. Specifically, we leverage distributed passive DNS data collection, and develop a machine learning-based system that aims to accurately identify a large variety of IoT devices based solely on their DNS fingerprints. Our system is independent of whether the devices reside behind a NAT or other middleboxes, or whether they are assigned an IPv4 or IPv6 address. We design IoTFinder as a multi-label classifier, and evaluate its accuracy in several different settings, including computing detection results over a third-party IoT traffic dataset and DNS traffic collected at a US-based ISP hosting more than 40 million clients. The experimental results show that our approach allows for accurately detecting many diverse IoT devices, even when they are hosted behind a NAT and their traffic is “mixed” with traffic generated by other IoT and non-IoT devices hosted in the same local network.
机译:能够枚举Internet上潜在易受攻击的IoT设备非常重要,因为它可以评估全球Internet风险,并使网络运营商能够检查其自身网络的卫生状况。为此,在本文中,我们提出了IoTFinder,这是一种高效,大规模的系统 被动 物联网设备的识别。具体来说,我们利用分布式被动DNS数据收集,并开发基于机器学习的系统,旨在仅基于设备的物联网设备准确地识别它们,从而准确识别它们的种类。 DNS指纹 。我们的系统与设备是否位于NAT或其他中间盒之后,或是否为其分配了IPv4或IPv6地址无关。我们将IoTFinder设计为多标签分类器,并在几种不同的设置中评估其准确性,包括通过第三方IoT流量数据集计算检测结果以及在托管超过4000万客户的美国ISP处收集的DNS流量。实验结果表明,即使将它们托管在NAT之后并且其流量与由同一本地网络中托管的其他IoT和非IoT设备生成的流量“混合”,我们的方法也可以准确检测许多不同的IoT设备。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号