Arman Pashamokhtari

dblp:268/1715 · DBLP profile ↗
← Back
7ranked-venue papers
7as first author
6since 2021 · last 2024
0000-0002-0663-5061ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 6 first-author · 5 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 Efficient IoT Traffic Inference: From Multi-view Classification to Progressive Monitoring
abstract
Machine learning-based techniques have proven to be effective in Internet-of-Things (IoT) network behavioral inference. Existing works developed data-driven models based on features from network packets and/or flows, but mainly in a static and ad-hoc manner, without adequately quantifying their gains versus costs. In this article, we develop a generic architecture that comprises two distinct inference modules in tandem, which begins with IoT network behavior classification followed by continuous monitoring. In contrast to prior relevant works, our generic architecture flexibly accounts for various traffic features, modeling algorithms, and inference strategies. We argue quantitative metrics are required to systematically compare and efficiently select various traffic features for IoT traffic inference. This article 1 makes three contributions: (1) For IoT behavior classification, we identify four metrics, namely, cost, accuracy, availability, and frequency, that allow us to characterize and quantify the efficacy of seven sets of packet-based and flow-based traffic features, each resulting in a specialized model. By experimenting with traffic traces of 25 IoT devices collected from our testbed, we demonstrate that specialized-view models can be superior to a single combined-view model trained on a plurality of features by accuracy and cost. We also develop an optimization problem that selects the best set of specialized models for a multi-view classification. (2) For monitoring the expected IoT behaviors, we develop a progressive system consisting of one-class clustering models (per IoT class) at three levels of granularity. We develop an outlier detection technique on top of the convex hull algorithm to form custom-shape boundaries for the one-class models. We show how progression helps with computing costs and the explainability of detecting anomalies. (3) We evaluate the efficacy of our optimally selected classifiers versus the superset of specialized classifiers by applying them to our IoT traffic traces. We demonstrate how the optimal set can reduce the processing cost by a factor of six with insignificant impacts on the classification accuracy. Also, we apply our monitoring models to a public IoT dataset of benign and attack traces and show they yield an average true-positive rate of 94% and a false-positive rate of 5%. Finally, we publicly release our data (training and testing instances of classification and monitoring tasks) and code for convex hull-based one-class models.
Arman Pashamokhtari, Gustavo Batista, Hassan Habibi Gharakheili
ACM Trans. Internet Things1
2023 Combining Stochastic and Deterministic Modeling of IPFIX Records to Infer Connected IoT Devices in Residential ISP Networks
abstract
Residential Internet service providers (ISPs) today have limited device-level visibility into subscriber houses, primarily due to the network address translation (NAT) technology. The continuous growth of “unmanaged” consumer Internet of Things (IoT) devices combined with the rise of work-from-home makes home networks attractive targets to sophisticated cyber attackers. Volumetric attacks sourced from a distributed set of vulnerable IoT devices can impact ISPs by deteriorating the performance of their network, or even making them liable for being a carrier of malicious traffic. This article explains how ISPs can employ IP Flow Information eXport (IPFIX), a flow-level telemetry protocol available on their network, to infer connected IoT devices and ensure their cyber health without making changes to home networks. Our contributions are threefold: 1) we analyze more than nine million IPFIX records of 26 IoT devices collected from a residential testbed over three months and identify 28 flow features pertinent to their network activity that characterize the network behavior of IoT devices—we release our IPFIX records as open data to the public; 2) we train a multiclass classifier on stochastic attributes of IPFIX flows to infer the presence of certain IoT device types in a home network with an average accuracy of 96%. On top of the machine learning (ML) model, we develop a trust metric to track network activity of detected devices over time; and 3) finally, we develop deterministic models (DTs) of specific and shared cloud services consumed by IoTs, yielding an average accuracy of 92%. We show a combination of stochastic and DTs mitigates false positives in 75% of incidents at the expense of an average 7% reduction in true positives.
Arman Pashamokhtari, Norihiro Okui, Yutaka Miyake, Masataka Nakahara, Hassan Habibi Gharakheili
IEEE Internet Things J.1
2023 Dynamic Inference From IoT Traffic Flows Under Concept Drifts in Residential ISP Networks
abstract
Millions of vulnerable consumer IoT devices in home networks are the enabler for cyber crimes putting user privacy and Internet security at risk. Internet service providers (ISPs) are best poised to mitigate risks by automatically inferring active IoT devices per household and notifying users of vulnerable ones. Developing a scalable inference method that can perform robustly across thousands of home networks is a nontrivial task. This article focuses on the challenges of developing and applying data-driven inference models when labeled data of device behaviors is limited and the distribution of data changes across time and space domains (concept drifts). Our contributions are fourfold: 1) we collect and analyze more than six million network traffic flows of 24 types of consumer IoT devices from 12 real homes over six weeks to highlight the challenge of temporal and spatial concept drifts in network behaviors of IoT devices—we publicly release our training and testing instances data; 2) we analyze the performance of two inference strategies, namely global inference (a model trained on a combined set of all labeled data from training homes) and contextualized inference (several models each trained on the labeled data from a training home) in the presence of concept drifts; 3) to manage concept drifts, we develop a method that dynamically applies the “best” model (from a set) to network traffic of unseen homes during the testing phase, yielding better performance in a fifth of scenarios when the labels are available for the testing data (ideal but unrealistic settings); and 4) we develop a method to automatically select the best model without needing labels of unseen data (a realistic inference) and show that it can achieve 94% of the ideal model’s accuracy.
Arman Pashamokhtari, Norihiro Okui, Masataka Nakahara, Ayumu Kubota, Gustavo Batista, Hassan Habibi Gharakheili
IEEE Internet Things J.1
2022 PicP-MUD: Profiling Information Content of Payloads in MUD Flows for IoT Devices
abstract
The Manufacturer Usage Description (MUD) standard aims to reduce the attack surface for IoT devices by locking down their behavior to a formally-specified set of network flows (access control entries). Formal network behaviors can also be systematically and rigorously verified in any operating environment. Enforcing MUD flows and monitoring their activity in real-time can be relatively effective in securing IoT devices; however, its scope is limited to endpoints (domain names and IP addresses) and transport-layer protocols and services. Therefore, misconfigured or compromised IoTs may conform to their MUD-specified behavior but exchange unintended (or even malicious) contents across those flows. This paper develops PicP-MUD with the aim to profile the information content of packet payloads (whether unencrypted, encoded, or encrypted) in each MUD flow of an IoT device. That way, certain tasks like cyber-risk analysis, change detection, or selective deep packet inspection can be performed in a more systematic manner. Our contributions are twofold: (1) We analyze over 123K network flows of 6 transparent (e.g., HTTP), 11 encrypted (e.g., TLS), and 7 encoded (e.g., RTP) protocols, collected in our lab and obtained from public datasets, to identify 17 statistical features of their application payload, helping us distinguish different content types; and (2) We develop and evaluate PicP-MUD using a machine learning model, and show how we achieve an average accuracy of 99% in predicting the content type of a flow.
Arman Pashamokhtari, Arunan Sivanathan, Ayyoob Hamza, Hassan Habibi Gharakheili
WoWMoM1
2022 AdIoTack: Quantifying and refining resilience of decision tree ensemble inference models against adversarial volumetric attacks on IoT networks
Arman Pashamokhtari, Gustavo Batista, Hassan Habibi Gharakheili
Comput. Secur.1
2021 Inferring Connected IoT Devices from IPFIX Records in Residential ISP Networks
abstract
Residential ISPs today have limited device-level visibility into subscriber houses, primarily due to network address translation (NAT) technology. The continuous growth of "unmanaged" consumer IoT devices combined with the rise of work-from-home makes home networks attractive targets for cyber-attacks. Volumetric attacks sourced from a distributed set of vulnerable IoT devices can impact ISPs by deteriorating the performance of their network, or even making them liable for being a carrier of malicious traffic. This paper explains how ISPs can employ IPFIX (IP Flow Information eXport), a flow-level telemetry protocol available on their network, to infer connected IoT devices and ensure their cyber health without making changes to home networks. Our contributions are threefold: (1) We analyze near three million IPFIX records of 26 IoT devices collected from a residential testbed over three months and identify 28 features, pertinent to their network activity and services, that characterize the network behavior of IoT devices – we release our IPFIX records as open data to the public; (2) We develop a multi-class classifier to infer the presence of certain IoT device types in a home network from NATed IPFIX records. We also develop a Trust metric to track network activity of detected devices over time; and, (3) We evaluate the efficacy of our inferencing method by applying the trained classifier to IPFIX traces which yields an average accuracy of 96% in detecting device types. By computing a temporal measure of trust per each device, we highlight (on our testbed) a permanent behavioral change in third of devices as well as some intermittent behavioral changes in others.
Arman Pashamokhtari, Norihiro Okui, Yutaka Miyake, Masataka Nakahara, Hassan Habibi Gharakheili
LCN1
2020 PhD Forum Abstract: Dynamic Inference on IoT Network Traffic using Programmable Telemetry and Machine Learning
abstract
IoT networks continue to expand in various domains, from smart homes and campuses to smart cities and critical infrastructures. Due to the lack of appropriate security measures embedded in IoT devices, they are increasingly becoming the target of sophisticated cyber-attacks. Existing machine learning-based methods for monitoring and securing IoT networks are fragile, expensive, and inflexible, and hence unable to cost-effectively cope with the dynamic and complex nature of attacks. For my PhD thesis, the aim is to develop a robust, accurate, scalable, and cost-effective network monitoring solution for securing large IoT systems. To do so, we would require to dynamically measure and analyze certain portions of network traffic. Therefore, we employ programmable networking techniques to dynamically and selectively acquire necessary telemetry data (packets and/or flows of connected devices) fed to a collection of learning-based models (each specialized in certain protocols with specific granularity) to classify devices, monitor their activity, and detect malicious behaviors. Our preliminary results show that the signature analysis of selected signaling packets from 26 real IoT devices yields a reasonably accurate inference by progressively collecting telemetry data at manageable processing costs.
Arman Pashamokhtari
IPSN1