Empirical Study of System Resources Abused by IoT Attackers
Zijing Yin, Yiwen Xu, Chijin Zhou, Yu Jiang
Abstract
IoT devices have been under frequent attacks in recent years, causing severe impacts. Previous research has shown the evolution and features of some specific IoT malware families or stages of IoT attacks through offline sample analysis. However, we still lack a systematic observation of various system resources abused by active attackers and the malicious intentions behind these behaviors. This makes it difficult to design appropriate protection strategies to defend against existing attacks and possible future variants. In this paper, we fill this gap by analyzing 117,862 valid attack sessions captured by our dedicated high-interaction IoT honeypot, HoneyAsclepius, and further discover the intentions in our designed workflow. HoneyAsclepius enables high capture capability as well as continuous behavior monitoring during active attack sessions in real-time. Through a large-scale deployment, we collected 11,301,239 malicious behaviors originating from 50,594 different attackers. Based on this information, we further separate the behaviors in different attack sessions targeting distinct categories of system resources, estimate the temporal relations and summarize their malicious intentions behind. Inspired by such investigations, we present several key insights about abusive behaviors of the file, network, process, and special capability resources, and further propose practical defense strategies to better protect IoT devices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 27121e18-fbfd-4a40-a3f0-cfa148f74c9eCited by top-tier papers1
Ask how each one uses itBuilds on6
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Tracking Ransomware End-to-endDanny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi et al.S&P 2018 · 208 citations
- Understanding Linux MalwareEmanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide BalzarottiS&P 2018 · 203 citations
- Measurement and Analysis of Hajime, a Peer-to-peer IoT BotnetStephen Herwig, Katura Harvey, George Hughey, Richard Roberts et al.NDSS 2019 · 168 citations
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court et al.USENIX Security 2021 · 109 citations
Related papers
- HoneyPLC: A Next-Generation Honeypot for Industrial Control SystemsEfrén López-Morales, Carlos E. Rubio-Medrano, Adam Doupé, Yan Shoshitaishvili et al.CCS 2020 · 82 citations
- Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryChunmian Wang, Zhen Ling, Wenjia Wu, Qi Chen et al.INFOCOM 2022 · 10 citations
- To Catch a Ratter: Monitoring the Behavior of Amateur DarkComet RAT Operators in the WildBrown Farinholt, Mohammad Rezaeirad, Paul Pearce, Hitesh Dharmdasani et al.S&P 2017 · 48 citations
- Understanding and Securing Device Vulnerabilities through Automated Bug Report AnalysisXuan Feng, Xiaojing Liao, XiaoFeng Wang, Haining Wang et al.USENIX Security 2019 · 46 citations
- ARGUS: Context-Based Detection of Stealthy IoT Infiltration AttacksPhillip Rieger, Marco Chilese, Reham Mohamed, Markus Miettinen et al.USENIX Security 2023
