Faulds: A Non-Parametric Iterative Classifier for Internet-Wide OS Fingerprinting
Zain Shamsi, Daren B. H. Cline, Dmitri Loguinov
Abstract
Recent work in OS fingerprinting [41] , [42] has focused on overcoming random distortion in network and user features during Internet-scale SYN scans. These classification techniques work under an assumption that all parameters of the profiled network are known a-priori -the likelihood of packet loss, the popularity of each OS, the distribution of network delay, and the probability of user modification to each default TCP/IP header value. However, it is currently unclear how to obtain realistic versions of these parameters for the public Internet and/or customize them to a particular network being analyzed. To address this issue, we derive a non-parametric Expectation-Maximization (EM) estimator, which we call Faulds, for the unknown distributions involved in singleprobe OS fingerprinting and demonstrate its significantly higher robustness to noise compared to methods in prior work. We apply Faulds to a new scan of 67M webservers and discuss its findings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 18f29cd1-9cce-4a60-90ee-4135569cebe1Cited by top-tier papers4
- Acquisitional Rule-based Engine for Discovering Internet-of-Thing DevicesXuan Feng, Qiang Li, Haining Wang, Limin SunUSENIX Security 2018 · 139 citations
- LZR: Identifying Unexpected Internet ServicesLiz Izhikevich, Renata Teixeira, Zakir DurumericUSENIX Security 2021 · 63 citations
- Landing Reinforcement Learning onto Smart Scanning of The Internet of ThingsJian Qu, Xiaobo Ma, Wenmao Liu, Hongqing Sang et al.INFOCOM 2022 · 9 citations
- You Are What You Broadcast: Identification of Mobile and IoT Devices from (Public) WiFiLingjing Yu, Bo Luo, Jun Ma, Zhaoyu Zhou et al.USENIX Security 2020
Related papers
- Spoki: Unveiling a New Wave of Scanners through a Reactive Network TelescopeRaphael Hiesgen, Marcin Nawrocki, Alistair King, Alberto Dainotti et al.USENIX Security 2022
- Untangle: Multi-Layer Web Server FingerprintingCem Topcuoglu, Kaan Onarlioglu, Bahruz Jabiyev, Engin KirdaNDSS 2024
- Smudged Fingerprints: Characterizing and Improving the Performance of Web Application FingerprintingBrian Kondracki, Nick NikiforakisUSENIX Security 2024 · 4 citations
- AmpFuzz: Fuzzing for Amplification DDoS VulnerabilitiesJohannes Krupp, Ilya Grishchenko, Christian RossowUSENIX Security 2022
- Fingerprinting Deep Packet Inspection Devices by their AmbiguitiesDiwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman et al.CCS 2025
