Graph Based Analysis Technique for Identification of Key Functionalities in Malicious IoT Binaries
Mahesh Uttam Patil, Shailaja Patil, Santosh C. Wagaj · 2024
The paradigm of embedded systems being connected to internet have led to the evolution of Internet of Things (IoT). Considering that these devices are connected to home, enterprises, government and critical infrastructure, it has become prime target for the adversaries. Hence malwares on these IoT devices are now being witnessed. Analysis of these malware has become the need of the hour and requires special skills including reverse engineering. Hybrid approaches which include static and dynamic analysis have become popular even for IoT devices. For dynamic analysis to be successful prior static analysis is crucial. This paper highlights a technique of analyzing malicious binaries based on Graph theory. The proposed methodology extracts function call graph and derives the centrality metrics for analysis. To validate the technique, the results are compared across 6 variants of the popular real-world Gafgyt malware samples found in IoT devices including routers. The malware variants are chosen across two architectures i.e. ARM and x86 to demonstrate that the technique is agnostic of the architecture. The results depict that core functionalities of the malware can be traced using the degree and in-degree centrality metrics of graph. Further it was observed that with the proposed methodology, functions as less as 5 % are sufficient to derive core behavioral patterns of the malware.