Device Fingerprinting from Passive WiFi Traffic: Can Devices Be Uniquely Identified?

Sammanfattning

Wireless devices are widely used in homes, workplaces, and public spaces, making WiFi communication a pervasive part of everyday digital infrastructure. Even when payload encryption and Media-Access Control (MAC) address randomization are enabled, wireless devices can still expose metadata that may support device identification. Such identification could enable social engineering attacks, surveillance, and compromises of personal privacy. To examine this risk, this study investigated whether WiFi devices can be fingerprinted using only passively observed traffic, without decrypting payload content or actively interacting with the network. Data was collected through passive monitoring in a controlled home environment and analyzed using statistical methods, DBSCAN clustering, Uniform Manifold Approximation and Projection (UMAP) dimensionality reduction, and a cluster-based prediction model. The extracted features included probe request structure, vendor specific metadata, timing behavior, RSSI, and power-management indicators. The results show that combinations of passively observable metadata can reveal distinguishable patterns, particularly at the vendor and device-type level. Probe request metadata was the most informative feature category, while RSSI and sleep/wake behavior mainly provided contextual information. However, reliable identification of individual devices remained limited because similar devices often produced overlapping metadata patterns. The findings show that MAC address randomization and encryption reduce direct tracking, but do not fully prevent metadata-based classification or partial device re-identification

Beskrivning

Ämne/nyckelord

WiFi, device fingerprinting, security, metadata, passive monitoring, privacy.

Citation

Arkitekt (konstruktör)

Geografisk plats

Byggnad (typ)

Byggår

Modelltyp

Skala

Teknik / material

Index

Endorsement

Review

Supplemented By

Referenced By