• DocumentCode
    2843670
  • Title

    An Empirical Study of Passive 802.11 Device Fingerprinting

  • Author

    Neumann, Christoph ; Heen, Olivier ; Onno, Stéphane

  • Author_Institution
    Technicolor Security & Content Protection Labs., Rennes, France
  • fYear
    2012
  • fDate
    18-21 June 2012
  • Firstpage
    593
  • Lastpage
    602
  • Abstract
    802.11 device fingerprinting is the action of characterizing a target device through its wireless traffic. This results in a signature that may be used for identification, network monitoring or intrusion detection. The fingerprinting method can be active by sending traffic to the target device, or passive by just observing the traffic sent by the target device. Many passive fingerprinting methods rely on the observation of one particular network feature, such as the rate switching behavior or the transmission pattern of probe requests. In this work, we evaluate a set of global wireless network parameters with respect to their ability to identify 802.11 devices. We restrict ourselves to parameters that can be observed passively using a standard wireless card. We evaluate these parameters for two different tests: i) the identification test that returns one single result being the closest match for the target device, and ii) the similarity test that returns a set of devices that are close to the target devices. We find that the network parameters transmission time and frame inter-arrival time perform best in comparison to the other network parameters considered. Finally, we focus on inter-arrival times, the most promising parameter for device identification, and show its dependency from several device characteristics such as the wireless card and driver but also running applications.
  • Keywords
    security of data; system monitoring; telecommunication traffic; wireless LAN; fingerprinting method; frame interarrival time; global wireless network parameters; identification; intrusion detection; network monitoring; network parameters transmission time; passive 802.11 device fingerprinting; passive fingerprinting; standard wireless card; transmission pattern; wireless traffic; Databases; Histograms; IEEE 802.11 Standards; Monitoring; Probes; Wireless communication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems Workshops (ICDCSW), 2012 32nd International Conference on
  • Conference_Location
    Macau
  • ISSN
    1545-0678
  • Print_ISBN
    978-1-4673-1423-7
  • Type

    conf

  • DOI
    10.1109/ICDCSW.2012.8
  • Filename
    6258210