Measurement and Analysis of Hajime, a Peer-to-peer IoT Botnet
Stephen Herwig, Katura Harvey, George Hughey, Richard Roberts, Dave Levin
Abstract
The Internet of Things (IoT) introduces an unprecedented diversity and ubiquity to networked computing. It also introduces new attack surfaces that are a boon to attackers. The recent Mirai botnet showed the potential and power of a collection of compromised IoT devices. A new botnet, known as Hajime, targets many of the same devices as Mirai, but differs considerably in its design and operation. Hajime uses a public peer-to-peer system as its command and control infrastructure, and regularly introduces new exploits, thereby increasing its resilience. We show that Hajime’s distributed design makes it a valuable tool for better understanding IoT botnets. For instance, Hajime cleanly separates its bots into different peer groups depending on their underlying hardware architecture. Through detailed measurement—active scanning of Hajime’s peer-to-peer infrastructure and passive, longitudinal collection of root DNS backscatter traffic—we show that Hajime can be used as a lens into how IoT botnets operate, what kinds of devices they compromise, and what countries are more (or less) susceptible. Our results show that there are more compromised IoT devices than previously reported; that these devices use an assortment of CPU architectures, the popularity of which varies widely by country; that churn is high among IoT devices; and that new exploits can quickly and drastically increase the size and power of IoT botnets. Our code and data are available to assist future efforts to measure and mitigate the growing threat of IoT botnets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers15
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court et al.USENIX Security 2021 · 109 citations
- Examining Mirai's Battle over the Internet of ThingsHarm Griffioen, Christian DoerrCCS 2020 · 81 citations
- Dominance as a New Trusted Computing Primitive for the Internet of ThingsMeng Xu, Manuel Huber, Zhichuang Sun, Paul England et al.S&P 2019 · 61 citations
- IoTMosaic: Inferring User Activities from IoT Network Traffic in Smart HomesYinxin Wan, Kuai Xu, Feng Wang, Guoliang XueINFOCOM 2022 · 18 citations
- An Extensive Study of Residential Proxies in ChinaMingshuo Yang, Yunnan Yu, Xianghang Mi, Shujun Tang et al.CCS 2022 · 9 citations
Builds on2
Related papers
- How to Count Bots in Longitudinal Datasets of IP AddressesLeon Böck, Dave Levin, Ramakrishna Padmanabhan, Christian Doerr et al.NDSS 2023
- Could you clean up the Internet with a Pit of Tar? Investigating tarpit feasibility on Internet wormsHarm Griffioen, Christian DoerrS&P 2023
- Understanding Linux MalwareEmanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide BalzarottiS&P 2018 · 203 citations
- Hawkware: Network Intrusion Detection based on Behavior Analysis with ANNs on an IoT DeviceSunwoo Ahn, Hayoon Yi, Younghan Lee, Whoi Ree Ha et al.DAC 2020 · 13 citations
- BlackIoT: IoT Botnet of High Wattage Devices Can Disrupt the Power GridSaleh Soltan, Prateek Mittal, H. Vincent PoorUSENIX Security 2018 · 348 citations
