Investigation of IoT Botnets Behaviour and Analysis
Ramesh Singh Rawat, Manoj Diwakar, Prakash Srivastava · 2025
In this era of Industry 4.0, more and more digital devices are connecting to Internet. Further, industrial automation process is also propelling the demand of Internet of Things (IoT) infrastructure expansion. However, owing to the built-in security flaws in IoT devices, an increasing number of IoT devices are hijacked by taking advantage of their vulnerabilities. IoT devices tend to be more vulnerable to exploit than computer systems. In this paper, we surveyed the IoT botnets for their architecture, features, functions and threats caused by them. We illustrated the various covert and resilient tactics used by IoT botnets, which enable them to stay hidden and remain unnoticed for some time to evade the detection measures. We investigated the evasive behaviour - antidetection, anti-sandbox mechanism, and the common ports used by the IoT botnets for communication to stay undetected. Further, we performed the static analysis of the Mirai botnet binary ELF32 executable sample file. We illustrated the findings of the analysis. This research is useful in developing more robust detection and countermeasure models against these evolving IoT botnets. Finally, conclusion of static analysis is given together with some mitigation advices and defense practices.