The proliferation of Internet of Things (IoT) devices has introduced a multitude of security challenges. Following the notorious Mirai-based DDoS attack in 2016, which exploited vulnerable IoT devices, a wave of malware variants leveraging Mirai’s codebase emerged, including Satori, Reaper, Amnesia, and Masuta. These malicious entities capitalize on software vulnerabilities, posing a significant challenge to traditional defense mechanisms like firewalls, as they often bypass common detection methods such as open TELNET ports. This paper proposes a novel approach, dubbed ELITE (Early IoT Malware Detection using LightGBM), designed to preemptively identify IoT malware network activity during the scanning and infecting phases, prior to a full-blown attack. ELITE harnesses LightGBM, a gradient boosting framework, for efficient and accurate classification of edge device traffic. Complemented by a feature-rich packet traffic database, a policy module, and an optional packet sub-sampling component, ELITE offers a distributed and modular solution suitable for large-scale networks like those found in Internet Service Providers (ISPs) or enterprise environments. To assess the classification performance of ELITE, we perform extensive experiments, which show the effectiveness of the proposed method.The performance is quite effective in preventing IoT malware threats from worsening. Our findings therefore enrich the existing knowledge in the development of proactive defense against the new trends of the IoT botnets and the relevance of using machine learning in anomaly detection within IoT ecosystems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

IoT Network Analysis for Malware Detection

  • Khushi Arya,
  • Soummya Pal

摘要

The proliferation of Internet of Things (IoT) devices has introduced a multitude of security challenges. Following the notorious Mirai-based DDoS attack in 2016, which exploited vulnerable IoT devices, a wave of malware variants leveraging Mirai’s codebase emerged, including Satori, Reaper, Amnesia, and Masuta. These malicious entities capitalize on software vulnerabilities, posing a significant challenge to traditional defense mechanisms like firewalls, as they often bypass common detection methods such as open TELNET ports. This paper proposes a novel approach, dubbed ELITE (Early IoT Malware Detection using LightGBM), designed to preemptively identify IoT malware network activity during the scanning and infecting phases, prior to a full-blown attack. ELITE harnesses LightGBM, a gradient boosting framework, for efficient and accurate classification of edge device traffic. Complemented by a feature-rich packet traffic database, a policy module, and an optional packet sub-sampling component, ELITE offers a distributed and modular solution suitable for large-scale networks like those found in Internet Service Providers (ISPs) or enterprise environments. To assess the classification performance of ELITE, we perform extensive experiments, which show the effectiveness of the proposed method.The performance is quite effective in preventing IoT malware threats from worsening. Our findings therefore enrich the existing knowledge in the development of proactive defense against the new trends of the IoT botnets and the relevance of using machine learning in anomaly detection within IoT ecosystems.