arrow
Return

Improving IoT Botnet Investigation Using an Adaptive Network Layer

delete2019-02-11
delete49
delete
OA
AI
J
João Marcelo Ceron *
K
Klaus Steding-Jessen
C
Cristine Hoepers
L
Lisandro Zambenedetti Granville
C
Cíntia Borges Margi
DOI:10.3390/s19030727delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
IoT botnets have been used to launch Distributed Denial-of-Service (DDoS) attacks affecting the Internet infrastructure. To protect the Internet from such threats and improve security mechanisms, it is critical to understand the botnets' intents and characterize their behavior. Current malware analysis solutions, when faced with IoT, present limitations in regard to the network access containment and network traffic manipulation. In this paper, we present an approach for handling the network traffic generated by the IoT malware in an analysis environment. The proposed solution can modify the traffic at the network layer based on the actions performed by the malware. In our study case, we investigated the Mirai and Bashlite botnet families, where it was possible to block attacks to other systems, identify attacks targets, and rewrite botnets commands sent by the botnet controller to the infected devices.
Keywords:
malware
IoT
botnet
malware analysis
SDN
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Sensors cover
Sensors
IF:
3.5
Papers:
7.1W
Citations:
20.9W

Organization

U
Universidade Federal do Rio Grande do Sul
Scholars:
2.6W
Papers: 1.7W
Citations: 1.6W
U
university of twente
Scholars:
1.5W
Papers: 1.4W
Citations: 9
U
universidade de sao paulo
Scholars:
10.5W
Papers: 6.7W
Citations: 93
researcher View more organizations