VisiBot: Automated Detection and Visualization of IoT Botnets
Dimplesri Addagiri · 2025
The proliferation of Internet of Things (IoT) devices has introduced new challenges in cybersecurity, with the rise of botnets posing significant threats to networked systems. This paper presents VisiBot, a modular and automated botnet detection and visualization tool aimed at identifying and analyzing IoT botnets. Leveraging a globally distributed IoT honeypot network, VisiBot employs automated packet collection, malware analysis, and heuristic-based detection to identify Command & Control (C2) servers and Peer-To-Peer (P2P) botnets in real-time. Through extensive evaluation, VisiBot demonstrates its effectiveness in detecting various botnet variants, including Mirai, Bashlite, Hajime, and Mozi. Additionally, the paper discusses future enhancements to VisiBot, including improved malware unpacking procedures, expanded heuristic analysis techniques, and real-time honeypot data retrieval to further enhance its capabilities in preemptive botnet detection and mitigation.