Theoretical and Practical Intelligent Behavioral Fingerprinting
Date:
Tutorial session related to my PhD Thesis at NOMS 2022
Alberto Huertas1, Pedro M. Sánchez2, Muriel Franco1, Gérôme Bovet3, Gregorio Martínez2, Burkhard Stiller1
1 Communication Systems Group CSG, Department of Informatics IfI, University of Zurich UZH, Switzerland 2 Department of Information and Communications Engineering, University of Murcia, Spain 3 Cyber-Defence Campus within armasuisse Science & Technology, Thun, Switzerland
The Internet-of-Things (IoT) is strongly influencing the number of devices connected to the Internet. Nowadays, resource-constrained devices are used in many scenarios with particularities in terms of communications, data, and services. This heterogeneity increases the complexity of achieving one of their common challenges: optimizing their services’ efficiency. Today, a thriving challenge in behavior data science lies in creating behavior patterns (fingerprints) of devices and networks to optimize their performance and detect potential concerns, especially cyberthreats, at early stages. This tutorial provides an overview of application scenarios, devices, data sources, and processing techniques considered in behavioral fingerprinting. After that, the tutorial provides a practical vision of fingerprinting through three research projects using heterogeneous devices, data sources, and processing techniques to achieve different objectives. After that, the audience will practice with a guided exercise focused on using unsupervised Machine Learning techniques to detect a cyberattack affecting an IoT device. Finally, a selected set of lessons learned within this dedicated area of security management is presented, and future trends of behavioral fingerprinting are outlined.
