IoT - Side Room (Thu, 14:00)
This is a draft agenda: changes are still being made.
Internet scanning is a key signal for threat intelligence, but existing measurement approaches reveal where scans originate, not what kind of device is behind them, limiting the ability to distinguish IoT-botnet activity from general-purpose scanning at the network-operator level.
We develop a methodology to classify IoT and non-IoT devices from a single TCP SYN packet, requiring neither active probing nor flow reconstruction. This gives operators device-level visibility into traffic, enabling …
The Internet of Things (IoT) is a common attack vector and cause for privacy concerns. Protecting against such attacks while also protecting the privacy of its users often conflicts with constrained resources we find in the IoT. We present DNS over the Constrained Application Protocol (CoAP), a new protocol to counter such attacks by encrypting queries, similar to DNS over TLS, HTTPS, or QUIC. In contrast to those protocols for the "big" Internet, DNS over CoAP is designed to encrypt queries fr…