IOT security system to avoid botnet threats for mobile application

S. Keerthika, K. Christina Praisy, Swetha Popat Kolekar, A. Lakshmi Shrri, V. Anusuya Devi, V. Kalaivani · AIP conference proceedings · 2022

Botnet is a collection of internet-connected devices infected by malware which allows hackers to control them. Cyber criminals use botnets to instigate botnet attacks, which include malicious activities such as credentials leaks, unauthorized access, data theft and DDoS attacks. Botnets can also affect mobile phones and the bot which attacks a mobile is called a mobile bot. A mobile bot is a type of malware that runs automatically once installed on a mobile device without mobile antivirus software. It gains complete access to the device and its contents, and starts communicating with and receiving instructions from one or more command and control servers. Mobile botnet also includes a major threat which is Distributed Denial Of Service (DDoS) attack. A DDoS attack is a type of Botnet which is used to overwhelm a target website with fake traffic. This attack aims at disrupting the normal functioning of a server, network or mobile phones by means of trafficking. Here, trafficking means overwhelming the device by sending multiple repeated malicious requests from various IP Addresses. This proposed work aims at avoiding trafficking which is the root cause of the DDoS attack and avoiding trafficking of the malicious unknown IP addresses. The proposed system “Firewall Security Application using Command and Control method” which allows only the IP Addresses that are of interest to the device and denies all the malicious requests targeting the device. This security application when installed in a device checks and detects if there is any unknown IP address entering the device, thereby denying the unknown requests.

Read the paper · More papers on PaperTik