Device Fingerprinting from Passive WiFi Traffic: Can Devices Be Uniquely Identified?
| dc.contributor.author | Bergström, Miranda | |
| dc.contributor.author | Dahl, Ludvig | |
| dc.contributor.author | Detterfelt, Måns | |
| dc.contributor.author | Jiang Safady, Rima | |
| dc.contributor.author | Statelova, Monika | |
| dc.contributor.author | Osman Uzel, Seyyid | |
| dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
| dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
| dc.contributor.examiner | Linde, Arne | |
| dc.contributor.supervisor | Hashim Changrampadi, Mohamed | |
| dc.date.accessioned | 2026-08-07T07:51:04Z | |
| dc.date.issued | 2026 | |
| dc.date.submitted | ||
| dc.description.abstract | Wireless devices are widely used in homes, workplaces, and public spaces, making WiFi communication a pervasive part of everyday digital infrastructure. Even when payload encryption and Media-Access Control (MAC) address randomization are enabled, wireless devices can still expose metadata that may support device identification. Such identification could enable social engineering attacks, surveillance, and compromises of personal privacy. To examine this risk, this study investigated whether WiFi devices can be fingerprinted using only passively observed traffic, without decrypting payload content or actively interacting with the network. Data was collected through passive monitoring in a controlled home environment and analyzed using statistical methods, DBSCAN clustering, Uniform Manifold Approximation and Projection (UMAP) dimensionality reduction, and a cluster-based prediction model. The extracted features included probe request structure, vendor specific metadata, timing behavior, RSSI, and power-management indicators. The results show that combinations of passively observable metadata can reveal distinguishable patterns, particularly at the vendor and device-type level. Probe request metadata was the most informative feature category, while RSSI and sleep/wake behavior mainly provided contextual information. However, reliable identification of individual devices remained limited because similar devices often produced overlapping metadata patterns. The findings show that MAC address randomization and encryption reduce direct tracking, but do not fully prevent metadata-based classification or partial device re-identification | |
| dc.identifier.coursecode | DATX11 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.12380/312086 | |
| dc.language.iso | eng | |
| dc.setspec.uppsok | Technology | |
| dc.subject | WiFi, device fingerprinting, security, metadata, passive monitoring, privacy. | |
| dc.title | Device Fingerprinting from Passive WiFi Traffic: Can Devices Be Uniquely Identified? | |
| dc.type.degree | Examensarbete på kandidatnivå | sv |
| dc.type.degree | Bachelor Thesis | en |
| dc.type.uppsok | M2 | |
| local.programme | Informationsteknik 300 hp (civilingenjör) | |
| local.programme | Datateknik 300 hp (civilingenjör) | |
| local.programme | Automation och mekatronik 300 hp (civilingenjör) |
