2020 IEEE European Symposium on Security and Privacy (EuroS&P) 2020
DOI: 10.1109/eurosp48549.2020.00037
|View full text |Cite
|
Sign up to set email alerts
|

IoTFinder: Efficient Large-Scale Identification of IoT Devices via Passive DNS Traffic Analysis

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1

Citation Types

0
35
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
5
4
1

Relationship

0
10

Authors

Journals

citations
Cited by 63 publications
(40 citation statements)
references
References 23 publications
0
35
0
Order By: Relevance
“…Most of these techniques are based on domain names that are contacted by devices since these can be easily obtained from captures, as they are not encrypted in DNS queries. Authors in [19] propose a model to fingerprint IoT devices behind a NAT (Network address translation) and identify them in an accurate and explainable way. Their idea is to profile each device with a list of domains associated with their query frequency.…”
Section: Related Workmentioning
confidence: 99%
“…Most of these techniques are based on domain names that are contacted by devices since these can be easily obtained from captures, as they are not encrypted in DNS queries. Authors in [19] propose a model to fingerprint IoT devices behind a NAT (Network address translation) and identify them in an accurate and explainable way. Their idea is to profile each device with a list of domains associated with their query frequency.…”
Section: Related Workmentioning
confidence: 99%
“…Proposed solutions, either rely on DNS data [6] that raise privacy concerns, or on in-situ scans by anti-virus software that are not scalable [7]. In this paper we describe a methodology for detecting the presence of IoT devices at subscriber lines at scale, using sparsely sampled flow captures (i.e., Net-Flow [8]).…”
Section: Our Approachmentioning
confidence: 99%
“…The approach from Perdisci et al [20] however, resembles our method of feature extraction as it uses the query URLs of a device's DNS requests. This approach uses the whole URL rather than the SLD and uses a naive document retrieval algorithm to match URLS to devices.…”
Section: Related Workmentioning
confidence: 99%