10 Years of IoT Malware: A Feature-Based Taxonomy
Benjamin Vignau, Raphaël Khoury, Sylvain Hallé · 2019
Over the past decade, there has been a rapidly growing interest in IoT-connected devices. But as is usually the case with computer systems and networks, malicious individuals soon noticed that these objects could be exploited for criminal purposes. The problem is particularly salient since the firmware used in many Internet connected devices were developed without taking into consideration the expertise and best security practices gained over the past several years by programmers in other areas. Multiple attacks on IoT devices took place therefore over the last decade, culminating with the largest ever recorded DDoS attack, the Mirai botnet, which took advantage of the weaknesses in the security of the IoT. In this survey, we seek to shed light on the evolution of the IoT malware. We compare the characteristic features of 16 of the most widespread IoT malware programs of the last decade and propose a novel methodology for classifying malware based on its behavioral features. Our study also highlights the common practice of feature reuse across multiple malware programs.