Automated Mining and Analysis of Packet Exchange Characteristics through Communication Packet Behavior
DOI:
https://doi.org/10.46604/aiti.2026.15564Keywords:
internet of things, cybersecurity, traffic analysis, machine learning, endpoint region predictionAbstract
Internet of things (IoT) devices often communicate with external services without clear visibility into their geographic destinations. This study aims to develop a gateway-based framework for predicting the region associated with remote endpoints from periodically collected connection records. Public endpoints are identified, enriched with MaxMind GeoIP2 attributes, and deduplicated into 4,320 unique instances across 18 region labels. Four classifiers are evaluated across four feature configurations to assess how prediction performance changes as GeoIP dependencies are reduced. Using only the transformed IP address, the Random Forest model achieved 92.94% accuracy and 85.24% macro F1 on the held-out test set without requiring GeoIP databases during inference. Temporal validation on endpoints first observed after training yielded 90.91% accuracy and 75.42% macro F1. These results demonstrate that part of the GeoIP-derived region mapping can be compressed into a compact deployable model, supporting communication transparency in IoT environments.
References
N. Dinh and S. Lim, “︁Performance Evaluations for IEEE 802.15.4-based IoT Smart Home Solution,”︁ International Journal of Engineering and Technology Innovation, vol. 6, no. 4, pp. 274–283, 2016.
T. Wu, F. Breitinger, and S. Niemann, “︁IoT Network Traffic Analysis: Opportunities and Challenges for Forensic Investigators?,”︁ Forensic Science International: Digital Investigation, vol. 38, article no. 301123, 2021.
A. Andrews, G. Oikonomou, S. Armour, P. Thomas, and T. Cattermole, “︁Reliable Identification of IoT Devices from Passive Network Traffic Analysis: Requirements and Recommendations,”︁ Proceedings of 2023 IEEE 9th World Forum on Internet of Things (WF-IoT), IEEE, pp. 1–6, 2023.
R. Soepeno, “︁Wireshark: An Effective Tool for Network Analysis,”︁ CYBV-Introductory Methods of Network Analysis, 2023.
M. Alyami, I. Alharbi, C. Zou, Y. Solihin, and K. Ackerman, “︁WiFi-based IoT Devices Profiling Attack Based on Eavesdropping of Encrypted WiFi Traffic,”︁ Proceedings of 2022 IEEE 19th Annual Consumer Communications & Networking Conference (CCNC), IEEE, pp. 385–392, 2022.
H. Kim, H. Lee, and H. Lim, “︁Performance of Packet Analysis between Observer and Wireshark,”︁ Proceedings of 2020 22nd International Conference on Advanced Communication Technology (ICACT), IEEE, pp. 268–271, 2020.
R. Rizal, I. Riadi, and Y. Prayudi, “︁Network Forensics for Detecting Flooding Attack on Internet of Things (IoT) Device,”︁ International Journal of Cyber-Security and Digital Forensics, vol. 7, no. 4, pp. 382–390, 2018.
D. Komosny, M. Voznak, and S. U. Rehman, “︁Location Accuracy of Commercial IP Address Geolocation Databases,”︁ Information Technology and Control, vol. 46, no. 3, pp. 333–344, 2017.
J. P. Chaudhari, K. P. Patel, H. K. Mewada, H. S. Jayswal, Y. P. Kosta, K. S. Bhagat, et al., “︁Recursive Feature Elimination and Optimized Hybrid Ensemble Approach for Early Heart Disease Prediction,”︁ Advances in Technology Innovation, vol. 10, no. 1, pp. 58–71, 2025.
P. Asrodia and H. Patel, “︁Network Traffic Analysis Using Packet Sniffer,”︁ International Journal of Engineering Research and Applications, vol. 2, no. 3, pp. 854–856, 2012.
M. Gharaibeh, A. Shah, B. Huffaker, H. Zhang, R. Ensafi, and C. Papadopoulos, “︁A Look at Router Geolocation in Public and Commercial Databases,”︁ Proceedings of the 2017 Internet Measurement Conference, pp. 463–469, 2017.
J. Martin, T. Mayberry, C. Donahue, L. Foppe, L. Brown, C. Riggins, et al., “︁A Study of MAC Address Randomization in Mobile Devices and When it Fails,”︁ arXiv preprint arXiv:1703.02874, 2017.
S. Ness, V. Eswarakrishnan, H. Sridharan, V. Shinde, N. V. P. Janapareddy, and V. Dhanawat, “︁Anomaly Detection in Network Traffic Using Advanced Machine Learning Techniques,”︁ IEEE Access, vol. 13, pp. 16133–16149, 2025.
Z. Chen, Z. Li, J. Huang, S. Liu, and H. Long, “︁An Effective Method for Anomaly Detection in Industrial Internet of Things Using XGBoost and LSTM,”︁ Scientific Reports, vol. 14, no. 1, article no. 23969, 2024.
M. A. A. da Cruz, L. R. Abbade, P. Lorenz, S. B. Mafra, and J. J. P. C. Rodrigues, “︁Detecting Compromised IoT Devices through XGBoost,”︁ IEEE Transactions on Intelligent Transportation Systems, vol. 24, no. 12, pp. 15392–15399, 2022.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Shao-Chien Lin, Tse-Chuan Hsu

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Submission of a manuscript implies: that the work described has not been published before that it is not under consideration for publication elsewhere; that if and when the manuscript is accepted for publication. Authors can retain copyright in their articles with no restrictions. is accepted for publication. Authors can retain copyright of their article with no restrictions.
Since Jan. 01, 2019, AITI will publish new articles with Creative Commons Attribution Non-Commercial License, under The Creative Commons Attribution Non-Commercial 4.0 International (CC BY-NC 4.0) License.
The Creative Commons Attribution Non-Commercial (CC-BY-NC) License permits use, distribution and reproduction in any medium, provided the original work is properly cited and is not used for commercial purposes.
