Skip to content

Internet-Scale Classification of IoT and Non-IoT Devices from a Single Packet

This is a draft agenda: changes are still being made.

Speaker:
Muhammad Sangeen, PhD Candidate, University of Twente
Date:
Time:
Room:
Side Room
Session:
IoT
Duration:
30 min
Transcript:
Not Available
Meetecho chat:
Not Available
Type:
Talk
Slides:
—
Recording:
Not Available
Add to calendar

Abstract

Internet scanning is a key signal for threat intelligence, but existing measurement approaches reveal where scans originate, not what kind of device is behind them, limiting the ability to distinguish IoT-botnet activity from general-purpose scanning at the network-operator level.

We develop a methodology to classify IoT and non-IoT devices from a single TCP SYN packet, requiring neither active probing nor flow reconstruction. This gives operators device-level visibility into traffic, enabling them to flag IoT devices appearing on infrastructure where they are not expected, such as cameras or smart appliances communicating from networks where only servers or user devices are expected. Because it relies only on a single TCP SYN packet, the approach can be deployed at any vantage point observing TCP traffic, including CGNAT borders and IXP mirrors.

We build a multi-source fingerprint dataset from 224 IoT devices across six testbeds, combined with a non-IoT fingerprint database. We show that a small set of SYN header fields, primarily related to TCP receive-buffer configuration, separates the two populations. Our approach combines exact fingerprint matching with a classifier that generalises to previously unseen devices, correctly classifying over 90% of them at a false positive rate below 0.2%.

We apply this approach to 30 days of traffic from the University of California, San Diego (UCSD) Network Telescope, comprising 3.2 trillion packets from 10.8 million distinct sources. We find that IoT devices constitute approximately 6% of scanning hosts but contribute under 1% of total scan volume. Non-IoT hosts account for most scan traffic, driven by few high-volume scanners. IoT contributes to Internet scanning by breadth rather than volume: many devices each scan slowly, a pattern consistent with IoT botnet behaviour.

We also characterise differences in target ports, scanning behaviour, and geographic origin between IoT and non-IoT devices. These results provide operators with device-level insight into the sources and behaviour of Internet scanning activity.

Recording

Video will be added soon.

Speaker

Muhammad Sangeen

Muhammad Sangeen

I am a PhD candidate in the Design and Analysis of Communication Systems (DACS) group at the University of Twente, Netherlands, where I began my PhD in July 2025.

My research focuses on threat intelligence generation using network telescope data and RIPE Atlas measurements to analyze Internet-wide traffic and detect and classify anomalous network behavior.

Rate this talk

Rating will open: Monday, 26 October 2026 09:00 (+0200).