https://www.mdu.se/

mdu.sePublications
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Enhancing Smart Home Security through IoT Device Fingerprinting Using Machine Learning: Enhancing Smart Home Security using ML
Mälardalen University, School of Innovation, Design and Engineering.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Smart-home networks host heterogeneous IoT devices that expand the attack surface while limiting on-device defenses. This thesis investigates whether flow-based machine learning can enhance smart-home intrusion detection without payload inspection. Using the public CIC-IoT-2023 corpus and home-lab traces converted to Zeek bidirectional flows, we evaluate three supervised classifiers (Random Forest, XGBoost, LightGBM) and two one-class detectors (Isolation Forest, Autoencoder). The pipeline prioritizes recall on malicious flows via validation-time thresholding and examines feature ablation to approach gateway-feasible models. Results across the two datasets indicate that ensemble classifiers can reach the recall target with moderate false-alarm rates, while one-class methods provide complementary coverage for previously unseen behaviours at a higher falsepositive cost. Feature pruning retains effectiveness with a compact subset of timing, size, and flag features, supporting edge deployment under privacy constraints. We discuss ethical considerations of flow-only analysis, operational trade-offs for recall-first alerting, and practical steps toward integration on resource-constrained hubs. The work contributes a payload-agnostic evaluation of ML-based fingerprinting for smart-home security and a methodology for balancing detection quality with deployability.

Place, publisher, year, edition, pages
2025. , p. 46
Keywords [en]
Smart Home Security, Internet of Things (IoT), IoT Device Fingerprinting, Machine Learning (ML), Flow-based Intrusion Detection, Zeek, Suricata, Random Forest (RF), XGBoost (XGB), LightGBM (LGBM), Isolation Forest (IF), Autoencoder (AE), CIC-IoT-2023 Dataset, Network Traffic Analysis, Anomaly Detection, Cybersecurity in Smart Homes, Recall-first Intrusion Detection, Payload-agnostic Detection, Edge Deployment, Privacy-preserving Intrusion Detection
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:mdh:diva-73522OAI: oai:DiVA.org:mdh-73522DiVA, id: diva2:2002838
Subject / course
Computer Science
Available from: 2025-10-10 Created: 2025-10-02 Last updated: 2025-10-10Bibliographically approved

Open Access in DiVA

Enhancing_Smart_Home_Security_through_IoT_Device_Fingerprinting_Using_Machine_Learning__Haris_Adrović(1410 kB)41 downloads
File information
File name FULLTEXT01.pdfFile size 1410 kBChecksum SHA-512
d9dc4e6d7cae411a5b19873290cef3163fa8fe3327c1928c7727da2932afb5907de9a226a361a6e5e8e6003bd7fe5386f02a2e2e794d75b334221726a7035982
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Adrović, Haris
By organisation
School of Innovation, Design and Engineering
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 920 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf