MADEA: A Malware Detection Architecture for IoT Blending Network Monitoring and Device Attestation

Renascence Tarafder Prapty, Rahmadi Trimananda, Sashidhar Jakkamsetti, Gene Tsudik, Athina P. Markopoulou · 2025

Internet-of-Things (IoT) devices are vulnerable to malware and require new mitigation techniques due to their limited resources. To that end, previous research has used periodic Remote Attestation ($R A$) or Traffic Analysis ($\mathcal{T} A$) to detect malware in IoT devices. However,$\mathcal{R A}$is expensive, and$\mathcal{T}$A only raises suspicion without confirming malware presence. To solve this, we design MADEA, the first system that blends$\mathcal{R A}$and$\mathcal{T A}$to offer a comprehensive approach to malware detection for IoT.$\mathcal{T}$A builds profiles of expected packet traces during benign operations of each device and then uses them to detect malware from network traffic in real-time.$\mathcal{R A}$confirms the presence or absence of malware on the device. MADEA achieves 100 % true positive rate. It also outperforms other approaches with$160 \times$faster detection time. Finally, without MADEA, effective periodic$\mathcal{R A}$can consume at least$\sim 14 \times$the amount of energy that a device needs in one hour.

Read the paper · More papers on PaperTik