Accurate identification of IoT devices is important for security management and policy enforcement. Existing approaches typically learn device signatures from packets or flow records. These methods operate on low-level communication observations whose traffic patterns may vary across deployments, software versions, and user interactions. This paper studies device identification using Manufacturer Usage Description (MUD) profiles. MUD profiles describe device behavior using Access Control Entries (ACEs), where each ACE represents a behavioral primitive consisting of protocol, endpoint, direction, and port semantics derived from device communication policy. Our contributions are threefold. First, using 28 publicly available MUD profiles containing 1,023 ACE instances, we construct ACE-level semantic representations from compact behavioral text and analyze their geometric properties. ACE-level representations preserve device-level behavioral distinctions more effectively than whole-profile embeddings and remain effective after whitening calibration. Second, we evaluate semantic ACE matching under controlled runtime variations, including unseen ACEs, drifted hostnames, and partial runtime observation. Exact ACE matching performs well when the overlap with the canonical MUD profile remains high, but degrades sharply when the overlap becomes sparse or disappears. In contrast, semantic ACE matching preserves useful identification evidence across these conditions. Third, we evaluate the same approach on real IoT traffic traces comprising more than 800,000 observed flows. Exact overlap remains the strongest signal when stable overlap exists, while semantic ACE matching provides stronger identification evidence during the early stages of observation, frequently retains the correct device among the highest-ranked candidates, and remains effective under sparse-overlap runtime traffic.


翻译:物联网设备的准确识别对安全管理与策略实施至关重要。现有方法通常从数据包或流记录中学习设备签名,但这些方法依赖低层次通信观测数据,其流量模式可能因部署环境、软件版本及用户交互而异。本文研究利用制造商使用说明(MUD)配置文件进行设备识别。MUD配置文件通过访问控制条目(ACE)描述设备行为,每个ACE代表一种行为原语,包含源自设备通信策略的协议、端点、方向及端口语义。我们的贡献包括三方面:其一,利用包含1,023个ACE实例的28个公开MUD配置文件,从紧凑行为文本中构建ACE级语义表征并分析其几何特性。相较于整体配置文件嵌入,ACE级表征能更有效保留设备级行为区分度,且经白化校准后仍保持有效性;其二,在可控运行时变条件下(包括未见ACE、漂移主机名及部分运行时观测)评估语义ACE匹配性能。当与规范MUD配置文件重叠度较高时,精确ACE匹配表现良好,但当重叠度稀疏或消失时性能急剧下降。相比之下,语义ACE匹配能在这些条件下保留有效识别证据;其三,在包含超过80万条观测流的真实物联网流量轨迹上评估相同方法。当存在稳定重叠时,精确重叠仍是最强信号,但语义ACE匹配在观测早期提供更强识别证据,通常能将正确设备保留在最高排名候选集中,并在稀疏重叠运行时流量下保持有效性。

0
下载
关闭预览

相关内容

国家标准《物联网 群智感知 技术架构》(征求 意见稿)
《物联网参考体系结构》国家标准
专知会员服务
30+阅读 · 2024年6月22日
《国防和安全系统中的物联网 (IoT): 文献综述》
专知会员服务
34+阅读 · 2023年11月22日
《通过网络隐蔽渠道开发物联网》74页论文
专知会员服务
31+阅读 · 2023年10月28日
TPAMI 2022 | 最新综述:基于不同数据模态的行为识别
专知会员服务
53+阅读 · 2022年7月2日
【AIOT】2020年中国智能物联网(AIoT)白皮书|附下载
产业智能官
32+阅读 · 2020年3月13日
我所了解的物联网设备测试方法(硬件篇)
FreeBuf
12+阅读 · 2019年2月12日
一文读懂目标检测:R-CNN、Fast R-CNN、Faster R-CNN、YOLO、SSD
七月在线实验室
11+阅读 · 2018年7月18日
深度学习的目标检测技术演进:R-CNN、Fast R-CNN、Faster R-CNN
数据挖掘入门与实战
13+阅读 · 2018年4月6日
AAAI 2018 行为识别论文概览
极市平台
18+阅读 · 2018年3月20日
北大新技术:利用WiFi设备进行人体行为识别!
全球人工智能
12+阅读 · 2018年2月7日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Arxiv
0+阅读 · 6月10日
VIP会员
最新内容
俄乌无人机战争的六大启示
专知会员服务
4+阅读 · 今天7:07
《无人机空中监控:通信实验洞察》
专知会员服务
3+阅读 · 今天7:05
从采集到决策:美军视角下的战术情报范式重构
《履带式无人地面战车技术发展现状》
专知会员服务
6+阅读 · 8月2日
《无人机脆弱性利用:网络空间力量的新域》
专知会员服务
6+阅读 · 8月1日
美空军如何将人工智能从战场部署至后方机关
专知会员服务
13+阅读 · 7月31日
相关基金
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员