Unveiling Behavioral Transparency of Protocols Communicated by IoT Networked Assets (Full Version)
Savindu Wannigama (1), Arunan Sivanathan (2), Ayyoob Hamza (2) and, Hassan Habibi Gharakheili (2) ((1) Department of Computer Engineering,, University of Peradeniya, Sri Lanka. (2) School of EE&T, UNSW Sydney,, Australia.)

TL;DR
This paper analyzes IoT network traffic to characterize device behaviors and identify protocols, developing models that improve detection accuracy and provide insights into device-specific communication patterns.
Contribution
It introduces a systematic protocol signature model, analyzes traffic from six protocols across ten IoT devices, and publicly shares the dataset and findings.
Findings
High accuracy in protocol detection with minimal false positives.
Distinct behavioral patterns observed across different IoT devices.
Models effectively describe protocol signatures even on non-standard ports.
Abstract
Behavioral transparency for Internet-of-Things (IoT) networked assets involves two distinct yet interconnected tasks: (a) characterizing device types by discerning the patterns exhibited in their network traffic, and (b) assessing vulnerabilities they introduce to the network. While identifying communication protocols, particularly at the application layer, plays a vital role in effective network management, current methods are, at best, ad-hoc. Accurate protocol identification and attribute extraction from packet payloads are crucial for distinguishing devices and discovering vulnerabilities. This paper makes three contributions: (1) We process a public dataset to construct specific packet traces pertinent to six standard protocols (TLS, HTTP, DNS, NTP, DHCP, and SSDP) of ten commercial IoT devices. We manually analyze TLS and HTTP flows, highlighting their characteristics, parameters,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting · Advanced Malware Detection Techniques
