Using JA4+ Fingerprints for Device Identification in Encrypted IoT Networks
Gemma B. Vate, Jorge E. López de Vergara, Iván González, Gustavo Sutter, Luis de Pedro
Source record
Source: Crossref
Published: Jul 27, 2026
DOI: 10.20944/preprints202607.1933.v1
Open original source ↗Source abstract
This paper investigates whether JA4+ fingerprint decomposition improves passive identification of Internet of Things (IoT) devices in encrypted network environments. As TLS encryption and privacy-preserving mechanisms such as Encrypted Client Hello reduce the visibility of application-layer metadata, traditional payload- and domain-based identification techniques become less effective. JA4+ fingerprints provide an alternative approach by extracting observable characteristics from TLS handshakes, certificates, and transport-layer metadata without requiring traffic decryption. The proposed methodology evaluates different JA4+ fingerprint combinations for IoT device identification using traffic traces from the CICIoT2023 dataset. Traffic traces were processed with Zeek to extract the JA4+ fingerprint family, which was evaluated using dictionary-based classification and Random Forest models. Compact fingerprint representations were compared with decomposed protocol-level features to determine whether feature decomposition improves classification performance or enhances interpretability. Experimental results show that JA4+ fingerprints enable accurate IoT device identification using only passive encrypted traffic metadata. The compact JA4+ representation achieved the best classification performance among the evaluated configurations, reaching a Macro F1-score of 0.8333 and a Top-1 accuracy of 0.9091. Decomposed representations achieved comparable results but did not provide consistent classification improvements. These findings indicate that compact JA4+ fingerprints already preserve most of the discriminative information required for IoT device identification, making protocol-level decomposition unnecessary when maximizing classification performance. Nevertheless, decomposed representations remain valuable for interpretability and feature-level analysis. The results highlight the potential of JA4+ fingerprinting for scalable IoT security monitoring under increasingly encrypted network conditions.
Evidence graph
No public relationships recorded yet.
Integrity note: This page is a factual metadata record created by deterministic ingestion. It is not a claim that the work moves a mathematical frontier or has been independently verified.