Time-Series Anomaly Detection of Mozi Malware in IoT Devices Using Arima and Local Outlier Factor
Tünde Kaufman, József Katona · 2025
The increasing demand for IoT devices in industries has generated a high level of cybersecurity threats, with botnets including Mozi exploiting poor passwords and unpatched vulnerabilities to target networked infrastructure. Peer-to-peer (P2P) topology of Mozi, employing Distributed Hash Tables (DHTs) for Command-and-Control (C2) communications, makes it resistant to takedown operations and capable of high-scale Distributed Denial-of-Service (DDoS) attack, data exfiltration, and remote command execution. Traditional one-class, machine learning techniques such as OneClass Support Vector Machine (OCSVM) and Local Outlier Factor (LOF) have been widely used for discovering malwarerelated anomalies. However, such techniques require high labelled training datasets, whose availability in dynamically changing environments of malwares proves challenging. In this work, an AutoRegressive Integrated Moving Average (ARIMA)-based mechanism for discovering time-series anomalies in IoT-infected devices with Mozi infection is proposed. In an experimental setup using a Raspberry Pi running Pi-hole, baseline profiles of CPU consumption, RAM usage, and network activity are first established under normal conditions. Next, a system is subjected to a simulation of infection with Mozi malware and monitored for deviation with ARIMA forecasting and Local Outlier Factor (LOF) for discovering anomalies. By comparing predicted values with actual values, effective intrusion detection for malware-related anomalies is attained, providing a real-time, adaptive mechanism for early intrusion detection. In conclusion, with its effectiveness in discovering stealthy behaviour of malwares, employing ARIMA for discovering time-series anomalies in IoTinfected devices proves effective, and its employment in IoT cybersecurity aids in providing real-time mechanism for discovering threats for system admins and security professionals. As future work, a combination of ARIMA with deep neural networks such as Long Short-Term Memory (LSTM) networks will be employed for enhancing IoT malware accuracy for intrusion detection in IoT-infected devices.