Accurate and Early Detection of Iot Malware Via Dns Traffic Analysis with Deep Learning
Chenxing Zhang, Xiaoyan Hu, Xuanlin Pan, Guang Cheng, Ruidong Li, Hua Wu · 2025
Malware increasingly targets current Internet of Things (IoT) devices, causing significant economic losses. Accurate and early detection of malware is essential for defense. Existing IoT malware detection methods primarily analyze interactive traffic between compromised devices and C&C servers. Such detection needs to be performed while IoT devices are undergoing attacks, which still exposes IoT devices to danger. By analyzing real-world DNS traffic generated by IoT devices, we uncover that the DNS behavior patterns of benign IoT devices and malwareinfected devices differ. Therefore, this work proposes a method to accurately and early detect IoT malware via DNS traffic analysis with deep learning before attacks are launched, referred to as IoTMD-2D. IoTMD-2D first extracts a comprehensive set of DNS traffic features of IoT devices that effectively characterize DNS traffic behavioral patterns. Then, it integrates an attention-based LSTM to capture hidden relationships within domain names and a 1D-CNN to explore hidden patterns in DNS behavior-level features for generating feature representations that discriminate DNS traffic of benign IoT devices and malware-infected devices. Finally, IoTMD-2D accurately detects IoT malware based on the generated feature representation. Our experimental study on public IoT datasets demonstrates that our IoTMD-2D achieves an accuracy of 97.63 % in detecting IoT malware at an early stage via DNS traffic analysis.