Device Behavior Identification in Encrypted Home Security Camera Traffic

被引:1
|
作者
Liu, Shuhe [1 ,2 ]
Xu, Xiaolin [3 ]
Nan, Zhefeng [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Natl Comp Network Emergency Response Tech Team, Coordinat Ctr, Beijing, Peoples R China
关键词
Traffic Classification; Home Security Camera; IoT; Device Behavior; Convolutional Neural Network;
D O I
10.1109/ICTAI56018.2022.00135
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Home security cameras have become one of the most popular IoT devices due to rigid demand and low cost. However, these devices have become a disaster area where security issues such as cyberattacks and privacy breaches often occur. Researchers and intruders often employ traffic behavior analyzing methods to mine vulnerabilities. Nevertheless, the content transmitted by the HSC device contains a lot of dynamic interference video traffic, so it is hard to mine the behavior information of the HSC device from it. In contrast, the HSC device's non-TLS one-way response packets carry more efficient behavior information. Therefore, we propose an approach to identify device behavior based on the features of one-way response packets in non-TLS traffic. Based on the functional characteristics of the HSC device, we have a more fine-grained type division of behaviors, including eight behaviors and five states. In addition, we propose an automatic labeling approach based on countercurrent and operation logs for the problem of tedious and inaccurate manual labeling. Based on the features of three attributes, we compared the recognition effects of nine classifiers on two datasets, the real-world dataset and the IMC 2019 payload public dataset. Finally, the CNN-based classifier can achieve the most desirable identification effect with an accuracy rate of 97.47%, a recall rate of 97.42%, and an F1 score of 97.4%. The results show that the proposed approach can accurately identify the behavior and state of HSC at a fine-grained level. Moreover, this work has a significant reference value for device anomalous behavior detection and threat awareness.
引用
收藏
页码:881 / 885
页数:5
相关论文
共 50 条
  • [1] Automated Behavior Identification of Home Security Camera Traffic
    Liu, Shuhe
    Xu, Xiaolin
    Nan, Zhefeng
    [J]. 2023 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS, IJCNN, 2023,
  • [2] User Behavior Classification in Encrypted Cloud Camera Traffic
    Wang, Jibao
    Cao, Zigang
    Kang, Cuicui
    Xiong, Gang
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [3] HomeSpy: Inferring User Presence via Encrypted Traffic of Home Surveillance Camera
    Cheng, Yushi
    Ji, Xiaoyu
    Zhou, Xinyan
    Xu, Wenyuan
    [J]. 2017 IEEE 23RD INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2017, : 779 - 782
  • [4] Social Software User Behavior Identification for Encrypted Traffic
    Wu, Hua
    Wang, Lei
    Huang, Ruiqi
    Cheng, Guang
    Hu, Xiaoyan
    [J]. Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2024, 61 (09): : 2321 - 2333
  • [5] "Security begins at home": Determinants of home computer and mobile device security behavior
    Thompson, Nik
    McGill, Tanya Jane
    Wang, Xuequn
    [J]. COMPUTERS & SECURITY, 2017, 70 : 376 - 391
  • [6] Protocol identification of encrypted network traffic
    Gebski, Matthew
    Penev, Alex
    Wong, Raymond K.
    [J]. 2006 IEEE/WIC/ACM International Conference on Web Intelligence, (WI 2006 Main Conference Proceedings), 2006, : 957 - 960
  • [7] Browser Identification Based on Encrypted Traffic
    Liu, Changjiang
    Han, Jiesi
    Wei, Qiang
    [J]. PROCEEDINGS OF THE 2016 INTERNATIONAL CONFERENCE ON COMMUNICATIONS, INFORMATION MANAGEMENT AND NETWORK SECURITY, 2016, 47 : 360 - 363
  • [8] Research on malicious traffic identification technology in encrypted traffic
    Zeng, Yong
    Wu, Zhengyuan
    Dong, Lihua
    Liu, Zhihong
    Ma, Jianfeng
    Li, Zan
    [J]. Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2021, 48 (03): : 170 - 187
  • [9] ENiD: An Encrypted Web Pages Traffic Identification Based on Web Visiting Behavior
    Ge, Mengmeng
    Yu, Xiangzhan
    Sachidananda, Vinay Mysore
    Liu, Shangqing
    Liu, Likun
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS, ICDMW, 2022, : 593 - 601
  • [10] An IoT Device Identification Method over Encrypted Traffic Based on t-SNE Dimensionality
    Chen, Jiayun
    Zeng, Yong
    Liu, Zhihong
    Ma, Jianfeng
    Zhou, Tianci
    Liu, Jiale
    [J]. 2022 IEEE 21ST INTERNATIONAL CONFERENCE ON UBIQUITOUS COMPUTING AND COMMUNICATIONS, IUCC/CIT/DSCI/SMARTCNS, 2022, : 67 - 72