UPM Institutional Repository

On the passive fingerprinting attack for IoT device classification


Citation

Kamal, Tabina and Hashim, Fazirulhisyam and A Rasid, Mohd. Fadlee and Ahmad, Faisul Arif (2024) On the passive fingerprinting attack for IoT device classification. In: 7th IEEE International Symposium on Telecommunication Technologies 2024 (ISTT2024), 21-22 Oct. 2024, Langkawi Island, Malaysia. (pp. 138-143).

Abstract

The rapid growth of the Internet of Things (IoT), expected to exceed 29 billion devices by 2027, presents a significant security challenge. Device fingerprinting, which identifies devices through unique network traffic patterns, is a valuable security tool but can be exploited by attackers for undetectable reconnaissance. This paper explores the feasibility of passive traffic fingerprinting attacks from an attacker's perspective, focusing on a small-scale testbed with four devices from an undisclosed single vendor. Using minimal resources and open-source tools, traffic patterns were analyzed, confirming unique device behaviors. A Random Forest (RF) classifier was developed, demonstrating high precision with instances where 100% classification accuracy can be achieved in a specific experimental scenario using just two features: Source Port and Destination Port. Key aspects of the model included feature selection, hyperparameter tuning, and a tree depth optimization of 20. Notably, forward feature selection proved more effective than Principal Component Analysis (PCA). These preliminary results underscore the vulnerabilities of single-vendor IoT ecosystems and highlight the simplicity and replicability of this low-cost attack methodology. The ease with which attackers can implement this approach underscores the urgent need for robust defenses as IoT devices proliferate across various sectors.


Download File

[img] Text
121553.pdf - Published Version
Restricted to Repository staff only

Download (803kB)
Official URL or Download Paper: https://ieeexplore.ieee.org/document/10750595

Additional Metadata

Item Type: Conference or Workshop Item (Oral/Paper)
Divisions: Faculty of Engineering
DOI Number: https://doi.org/10.1109/ISTT63363.2024.10750595
Publisher: Institute of Electrical and Electronics Engineers
Keywords: Fingerprinting attack; IoT; Device classification
Depositing User: Mr. Mohamad Syahrul Nizam Md Ishak
Date Deposited: 06 Nov 2025 02:27
Last Modified: 06 Nov 2025 02:27
URI: http://psasir.upm.edu.my/id/eprint/121553
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item