Os Fingerprinting and Tethering Detection in Mobile Networks

Yi-Chao Chen,Yong Liao,Mario Baldi,Sung-Ju Lee,Lili Qiu
DOI: https://doi.org/10.1145/2663716.2663745
2014-01-01
Abstract:Fingerprinting the Operating System(OS) running on a device based on its traffic has several applications, such as NAT detection, policy enforcement in enterprise networks, and billing for shared access in mobile networks. In this paper, we propose to utilize several features in TCP/IP headers for OS identification, and use real traffic traces to evaluate the accuracy of fingerprinting. Our trace-driven study shows that several techniques that successfully fingerprint desktop OSes are not effective for fingerprinting mobile devices. Therefore, we propose new features for fingerprinting OSes on mobile devices. We also consider NAT/tethering detection, an important application of OS fingerprinting. We use the presence of multiple OSes from the same IP address along with TCP times-tamp, clock frequency, and boot time to detect tethering. Evaluation shows that our approach effectively detects tethering and outperforms existing schemes.
What problem does this paper attempt to address?