Characterizing DNS Behaviors of Internet of Things in Edge Networks.

Kuai Xu,Feng Wang,Sergio Jimenez,Andrew Lamontagne,John Cummings,Mitchell Hoikka
DOI: https://doi.org/10.1109/jiot.2020.2999327
IF: 10.6
2020-01-01
IEEE Internet of Things Journal
Abstract:The recent spate of cyber attacks and security threats toward Internet-of-Things (IoT) systems in smart cities, smart homes, and industry 4.0 calls for effective techniques to understand if, when, who, what IoT systems are exploited and compromised by Internet attackers. Toward this end, this article attempts to study DNS behavioral patterns of IoT systems in edge networks as a first step of characterizing their communication patterns and their interactions with IoT users, cloud servers, and other IoT or non-IoT devices in the same edge networks. Specifically, we analyze the temporal-spatial patterns of DNS behaviors of a variety of IoT systems in two dozens of edge networks and develop a simple yet effective Bloom filter mechanism for detecting anomalous traffic patterns based on unusual DNS queries and answers. To the best of our knowledge, this article is the first effort to systematically measure and monitor IoT network traffic from a DNS perspective for providing the security of heterogeneous IoT systems and ensuring IoT user privacy.
What problem does this paper attempt to address?