FINDING · DETECTION

IoT devices pose the primary false-positive risk: many IoT devices (printers, smart bulbs, cameras, vacuum cleaners) maintain very few sessions with a small number of fixed cloud IPs — behaviorally similar to a VPN client. In the CIC IoT 2022 dataset, only 2 devices were misclassified (a Google Nest Cam connecting to nexusapi-us1.dropcam.com and a device using Alibaba cloud) out of the full dataset with WINDOW=300 s and T=500 packets.

From 2024-almutairi-fingerprintingFingerprinting VPNs with Custom Router Firmware: A New Censorship Threat Model · §IV-B, §IV-C · 2024 · Consumer Communications \& Networking Conference

Implications

Tags

censors
generic
techniques
traffic-shape

Extracted by claude-sonnet-4-6 — review before relying.