Unveiling Hidden Structures: Multi-Platform IoT Malware Analysis Using Graph Embeddings
Remus M. Petrache, Ciprian Oprişa, Camelia Lemnaru · IEEE Access · 2025
This paper explores the use of control-flow information for detecting IoT malware across three different platforms. We propose a pipeline which extracts Control-Flow Graphs (CFGs) from program binaries, projects them onto an embedding space, then computes the similarity between the programs, in an attempt to explore whether this approach could help identify malware families across different platforms. We explore three different methods for generating graph embeddings – at node, edge and graph level – and find the latter to produce the best discrimination between malware families across different platforms. Moreover, we propose a computationally efficient method for computing graph similarities for graphs with multiple connected components, which achieves accuracy on par with the cubic Hungarian Algorithm matching approach. The evaluations performed on a dataset comprising of clean and malware samples belonging to 18 different families yielded that our CFG embedding similarity approach can easily identify most malware family samples belonging to the same family, for the same platform, obtaining AUC scores above 90%. The method shows strong potential for discriminating between malware families across different platforms. We are currently exploring cross-platform limitations and improvement points, and we share preliminary insights from our current work towards the end of the paper.