{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T04:11:19Z","timestamp":1779250279462,"version":"3.51.4"},"reference-count":80,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2023,12,16]],"date-time":"2023-12-16T00:00:00Z","timestamp":1702684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Things"],"published-print":{"date-parts":[[2024,2,29]]},"abstract":"<jats:p>Machine learning-based techniques have proven to be effective in Internet-of-Things (IoT) network behavioral inference. Existing works developed data-driven models based on features from network packets and\/or flows, but mainly in a static and ad-hoc manner, without adequately quantifying their gains versus costs. In this article, we develop a generic architecture that comprises two distinct inference modules in tandem, which begins with IoT network behavior classification followed by continuous monitoring. In contrast to prior relevant works, our generic architecture flexibly accounts for various traffic features, modeling algorithms, and inference strategies. We argue quantitative metrics are required to systematically compare and efficiently select various traffic features for IoT traffic inference.<\/jats:p>\n          <jats:p>\n            This article\n            <jats:xref ref-type=\"fn\">\n              <jats:sup>1<\/jats:sup>\n            <\/jats:xref>\n            makes three contributions: (1) For IoT behavior classification, we identify four metrics, namely, cost, accuracy, availability, and frequency, that allow us to characterize and quantify the efficacy of seven sets of packet-based and flow-based traffic features, each resulting in a specialized model. By experimenting with traffic traces of 25 IoT devices collected from our testbed, we demonstrate that specialized-view models can be superior to a single combined-view model trained on a plurality of features by accuracy and cost. We also develop an optimization problem that selects the best set of specialized models for a multi-view classification. (2) For monitoring the expected IoT behaviors, we develop a progressive system consisting of one-class clustering models (per IoT class) at three levels of granularity. We develop an outlier detection technique on top of the convex hull algorithm to form custom-shape boundaries for the one-class models. We show how progression helps with computing costs and the explainability of detecting anomalies. (3) We evaluate the efficacy of our optimally selected classifiers versus the superset of specialized classifiers by applying them to our IoT traffic traces. We demonstrate how the optimal set can reduce the processing cost by a factor of six with insignificant impacts on the classification accuracy. Also, we apply our monitoring models to a public IoT dataset of benign and attack traces and show they yield an average true-positive rate of 94% and a false-positive rate of 5%. Finally, we publicly release our data (training and testing instances of classification and monitoring tasks) and code for convex hull-based one-class models.\n          <\/jats:p>","DOI":"10.1145\/3625306","type":"journal-article","created":{"date-parts":[[2023,9,24]],"date-time":"2023-09-24T08:16:07Z","timestamp":1695543367000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Efficient IoT Traffic Inference: From Multi-view Classification to Progressive Monitoring"],"prefix":"10.1145","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0663-5061","authenticated-orcid":false,"given":"Arman","family":"Pashamokhtari","sequence":"first","affiliation":[{"name":"UNSW Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3482-8442","authenticated-orcid":false,"given":"Gustavo","family":"Batista","sequence":"additional","affiliation":[{"name":"UNSW Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9333-7635","authenticated-orcid":false,"given":"Hassan Habibi","family":"Gharakheili","sequence":"additional","affiliation":[{"name":"UNSW Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,12,16]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"A. Hamza. 2019. IoT Benign and Attack Traces. Retrieved from https:\/\/iotanalytics.unsw.edu.au\/attack-data.html"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.5555\/2207825"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2019.2940735"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00013"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3488661.3494031"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3266444.3266452"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3266444.3266452"},{"key":"e_1_3_2_9_2","unstructured":"Bitdefender. 2017. Infected Vending Machines Lamps other IoT Devices Shut Down University Network. Retrieved from https:\/\/bit.ly\/3NE6dPu"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS47738.2020.9110451"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68928-5"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2013.05.059"},{"key":"e_1_3_2_13_2","unstructured":"Cisco. 2012. Introduction to Cisco IOS NetFlow\u2014A Technical Overview. Retrieved from https:\/\/www.cisco.com\/c\/en\/us\/products\/collateral\/ios-nx-os-software\/ios-netflow\/prod_white_paper0900aecd80406232.html"},{"key":"e_1_3_2_14_2","unstructured":"Cyber Edge. 2020. Cyberthreat Defense Report. Retrieved from https:\/\/cyber-edge.com\/wp-content\/uploads\/2020\/03\/CyberEdge-2020-CDR-Report-v1.0.pdf"},{"issue":"83","key":"e_1_3_2_15_2","first-page":"1","article-title":"CVXPY: A Python-embedded modeling language for convex optimization","volume":"17","author":"Diamond S.","year":"2016","unstructured":"S. Diamond et\u00a0al. 2016. CVXPY: A Python-embedded modeling language for convex optimization. J. Mach. Learn. Res. 17, 83 (2016), 1\u20135.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00013"},{"key":"e_1_3_2_17_2","first-page":"1","article-title":"A survey on missing data in machine learning","volume":"8","author":"Tlamelo E.","year":"2021","unstructured":"E. Tlamelo et\u00a0al. 2021. A survey on missing data in machine learning. J. Big Data 8 (2021), 1\u201337.","journal-title":"J. Big Data"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9293"},{"key":"e_1_3_2_19_2","volume-title":"Proceedings of the USENIX Security Conference","author":"Feng X.","year":"2018","unstructured":"X. Feng, Q. Li, H. Wang, and L. Sun. 2018. Acquisitional rule-based engine for discovering Internet-of-Things devices. In Proceedings of the USENIX Security Conference."},{"key":"e_1_3_2_20_2","unstructured":"Forescout. 2016. Network Visibility Survey. Retrieved from http:\/\/bit.ly\/30LBGaf"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.4743746"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3229565.3229572"},{"key":"e_1_3_2_23_2","volume-title":"IoTSTEED: Bot-side Defense to IoT-based DDoS Attacks (Extended)","author":"Guo Hang","year":"2020","unstructured":"Hang Guo et\u00a0al. 2020. IoTSTEED: Bot-side Defense to IoT-based DDoS Attacks (Extended). Technical Report ISI-TR-738. USC\/Information Sciences Institute. Retrieved from https:\/\/bit.ly\/3ec9eGS"},{"key":"e_1_3_2_24_2","volume-title":"IoTSTEED: Bot-side Defense to IoT-based DDoS Attacks (Extended)","author":"Guo H.","year":"2020","unstructured":"H. Guo and J. Heidemann. 2020. IoTSTEED: Bot-side Defense to IoT-based DDoS Attacks (Extended). Technical Report ISI-TR-738. USC\/Information Sciences Institute. Retrieved from https:\/\/www.isi.edu\/%7ejohnh\/PAPERS\/Guo20b.html"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2019.2929511"},{"key":"e_1_3_2_26_2","volume-title":"Proceedings of the ACM SOSR","author":"Hamza A.","year":"2019","unstructured":"A. Hamza et\u00a0al. 2019. Detecting volumetric attacks on IoT devices via SDN-based monitoring of MUD activity. In Proceedings of the ACM SOSR."},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2997898"},{"issue":"1","key":"e_1_3_2_28_2","first-page":"1","article-title":"Verifying and monitoring IoTs network behavior using MUD profiles","volume":"19","author":"Hamza A.","year":"2022","unstructured":"A. Hamza et\u00a0al. 2022. Verifying and monitoring IoTs network behavior using MUD profiles. IEEE TDSC 19, 1 (2022), 1\u201318.","journal-title":"IEEE TDSC"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3229565.3229571"},{"key":"e_1_3_2_30_2","first-page":"1","article-title":"Attack and anomaly detection in IoT sensors in IoT sites using machine learning approaches","volume":"7","author":"Hasan M.","year":"2019","unstructured":"M. Hasan et\u00a0al. 2019. Attack and anomaly detection in IoT sensors in IoT sites using machine learning approaches. Internet Things J. 7 (2019), 1\u201314.","journal-title":"Internet Things J."},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2019.100059"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.imu.2021.100799"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2006.13086"},{"issue":"2","key":"e_1_3_2_34_2","article-title":"IoT inspector: Crowdsourcing labeled network traffic from smart home devices at scale","volume":"4","author":"Huang D. Yuxing","year":"2020","unstructured":"D. Yuxing Huang, N. Apthorpe, F. Li, G. Acar, and N. Feamster. 2020. IoT inspector: Crowdsourcing labeled network traffic from smart home devices at scale. ACM IMWUT 4, 2 (2020).","journal-title":"ACM IMWUT"},{"key":"e_1_3_2_35_2","unstructured":"IETF. 2013. Specification of the IP Flow Information Export (IPFIX) Protocol for the Exchange of Flow Information. Retrieved from https:\/\/tools.ietf.org\/html\/rfc7011"},{"key":"e_1_3_2_36_2","unstructured":"IETF. 2019. Manufacturer Usage Description Specification. Retrieved from https:\/\/tools.ietf.org\/html\/rfc8520"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3205023"},{"key":"e_1_3_2_38_2","volume-title":"Proceedings of the USENIX Security","author":"Kumar D.","year":"2019","unstructured":"D. Kumar et\u00a0al. 2019. All things considered: An analysis of IoT devices on home networks. In Proceedings of the USENIX Security."},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3139937.3139938"},{"key":"e_1_3_2_40_2","unstructured":"G. Lyon. 1997. Retrieved from Nmap. https:\/\/nmap.org\/"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3098243.3098264"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3098243.3098264"},{"issue":"6","key":"e_1_3_2_43_2","first-page":"1402","article-title":"AuDI: Toward autonomous IoT device-type identification using periodic communication","volume":"37","author":"Marchal S.","year":"2019","unstructured":"S. Marchal et\u00a0al. 2019. AuDI: Toward autonomous IoT device-type identification using periodic communication. IEEE JSAC 37, 6 (June2019), 1402\u20131412.","journal-title":"IEEE JSAC"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/IoTDI49375.2020.00027"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/3019612.3019878"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/MPRV.2018.03367731"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101968"},{"key":"e_1_3_2_48_2","volume-title":"Proceedings of the IEEE ICDCS","author":"Miettinen M.","year":"2017","unstructured":"M. Miettinen et\u00a0al. 2017. IoT SENTINEL: Automated device-type identification for security enforcement in IoT. In Proceedings of the IEEE ICDCS."},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","unstructured":"D. Mills. 1992. Network Time Protocol (Version 3) Specification Implementation and Analysis. Retrieved from https:\/\/www.rfc-editor.org\/info\/rfc1305","DOI":"10.17487\/rfc1305"},{"key":"e_1_3_2_50_2","unstructured":"MITRE. 2020. Common Vulnerabilities and Exposures. Retrieved from https:\/\/cve.mitre.org\/"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/WCNC.2019.8885429"},{"key":"e_1_3_2_52_2","volume-title":"Proceedings of the IEEE ICDCS","author":"Nguyen T. D.","year":"2019","unstructured":"T. D. Nguyen et\u00a0al. 2019. D\u00cfoT: A federated self-learning anomaly detection system for IoT. In Proceedings of the IEEE ICDCS."},{"key":"e_1_3_2_53_2","volume-title":"Proceedings of the IEEE ICDCS","author":"Nguyen T. D.","year":"2019","unstructured":"T. D. Nguyen et\u00a0al. 2019. D\u00cfoT: A federated self-learning anomaly detection system for IoT. In Proceedings of the IEEE ICDCS."},{"key":"e_1_3_2_54_2","unstructured":"Paloato. 2020. Unit 42 IoT Threat Report. Retrieved from https:\/\/start.paloaltonetworks.com\/unit-42-iot-threat-report"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/ETSecIoT50046.2020.00005"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/LCN52139.2021.9524954"},{"key":"e_1_3_2_57_2","unstructured":"A. Pashamokhtari et\u00a0al. 2022. IoT Traffic Instances. Retrieved from https:\/\/iotanalytics.unsw.edu.au\/smartinfer.html"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/WoWMoM54355.2022.00081"},{"key":"e_1_3_2_59_2","unstructured":"Red-Button. 2016. Dyn (DynDNS) DDoS Attack. Retrieved from https:\/\/www.red-button.net\/blog\/dyn-dyndns-ddos-attack"},{"key":"e_1_3_2_60_2","volume-title":"Proceedings of the ECML PKDD","author":"Reis D.","year":"2018","unstructured":"D. Reis et\u00a0al. 2018. One-class quantification. In Proceedings of the ECML PKDD."},{"key":"e_1_3_2_61_2","volume-title":"Convex Analysis","author":"Rockafellar R. T.","year":"1997","unstructured":"R. T. Rockafellar. 1997. Convex Analysis. Princeton Mathematical Series."},{"issue":"4","key":"e_1_3_2_62_2","first-page":"26","article-title":"A survey on IoT profiling, fingerprinting, and identification","volume":"3","author":"Safi M.","year":"2022","unstructured":"M. Safi et\u00a0al. 2022. A survey on IoT profiling, fingerprinting, and identification. ACM TIOT 3, 4, Article 26 (Sep.2022), 39 pages.","journal-title":"ACM TIOT"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/3419394.3423650"},{"key":"e_1_3_2_64_2","unstructured":"Salesforce. 2019. TLS Fingerprinting with JA3 and JA3S. Retrieved from https:\/\/engineering.salesforce.com\/tls-fingerprinting-with-ja3-and-ja3s-247362855967"},{"key":"e_1_3_2_65_2","unstructured":"SciPy. 2021. SciPy Convex Hull. Retrieved from https:\/\/docs.scipy.org\/doc\/scipy\/reference\/generated\/scipy.spatial.ConvexHull.html"},{"key":"e_1_3_2_66_2","volume-title":"Proceedings of the USENIX Security","author":"Sharma R. A.","year":"2022","unstructured":"R. A. Sharma et\u00a0al. 2022. Lumos: Identifying and localizing diverse hidden IoT devices in an unfamiliar environment. In Proceedings of the USENIX Security."},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIAFS.2018.8913346"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2984030"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2020.2971213"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2018.2866249"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/ANTS.2017.8384143"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939918.2939925"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/MTS.2018.2826079"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.25"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS56928.2023.10154292"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2865604"},{"key":"e_1_3_2_77_2","volume-title":"Proceedings of the NDSS","author":"Trimananda R.","year":"2019","unstructured":"R. Trimananda, J. Varmarken, A. Markopoulou, and B. Demsky. 2019. PingPong: Packet-level signatures for smart home device events. In Proceedings of the NDSS."},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41060-021-00259-z"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2018.11.013"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2018.11.013"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2017.02.007"}],"container-title":["ACM Transactions on Internet of Things"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3625306","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3625306","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:33Z","timestamp":1750178193000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3625306"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,16]]},"references-count":80,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,2,29]]}},"alternative-id":["10.1145\/3625306"],"URL":"https:\/\/doi.org\/10.1145\/3625306","relation":{},"ISSN":["2691-1914","2577-6207"],"issn-type":[{"value":"2691-1914","type":"print"},{"value":"2577-6207","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,16]]},"assertion":[{"value":"2022-12-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-09-07","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-12-16","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}