Response Generation Honeypot With Antidetection Capabilities for IoT Botnet Lifecycle Detection
Hao Tang, Hui Xin He, Yuming Feng, Junxiong Meng, Weizhe Zhang · IEEE Transactions on Artificial Intelligence · 2024
With the widespread use of edge computing, the security issues on the edge side of the Internet of Things (IoT) within the cloud-edge-device architecture are becoming increasingly severe, particularly with the growing threat posed by botnets. Existing research on IoT botnet detection primarily focuses on identifying infected devices, with significantly less emphasis on detecting the botnet scanning and propagation phases. Recognizing the importance of early detection to protect devices and networks, this article introduces RGPot—a novel honeypot based on a generative response model designed to detect the lifecycle of IoT botnets. RGPot consists of two core components: an interaction response module and a lifecycle detection module. In the interaction response module, generative adversarial networks (GANs) are employed to train models capable of generating responses to various types of request data. This enables RGPot to effectively simulate real IoT devices and provide tailored responses to deceive potential attackers. In the lifecycle detection module, a multilayer long short-term memory (LSTM) network is utilized to comprehensively detect the stages of an IoT botnet’s lifecycle, facilitating the precise identification of the stage at which the detected traffic data is located. To evaluate the efficacy of RGPot, we created a controlled experimental environment to assess its ability to capture IoT botnets and detect traffic data. The experimental results validate RGPot’s capability in botnet capture and antidetection, with an accuracy of 98.81% in detecting botnet lifecycles and a reduction in false positives of approximately 5%.