UCAM: Usage, Communication and Access Monitoring Based Detection System for IoT Botnets

Syed Muhammad Sajjad, Muhammad Yousaf · 2018

Botnets are being used for launching Distributed Denial of Service (DDoS) attacks causing massive financial loses to the enterprises. With the rise of low-cost, less protected Internet of Things (IoT) devices the likelihood of harm from botnets have also increased. Open sourcing the source code of Mirai IoT malware has provided the foundation step for the development and subsequent launch of variants of Mirai IoT botnets. Detecting such kind of threats is essential for the smooth operation of the Internet. Such security measures are basic requirements for the establishment of user trust on the Internet of Things devices. This paper presents UCAM: Usage, Communication and Access Monitoring Based Botnets Detection System for IoT. The proposed solution has three main components i.e. descriptor, monitor and comparator. Descriptor defines Device Usage, Communication and Access policies. Monitor observes the current state of device Usage, Communication and Access. Anomalies are Detected by the Comparator. Results show that the proposed detection system successfully detects Mirai IoT malware.

Read the paper · More papers on PaperTik