Published August 20, 2024 | Version v1
Conference paper Open

Macroscopic Insights of IoT Botnet Dynamics via AS-level Tolerance Assessment

  • 1. ROR icon King Abdulaziz University
  • 2. Okta, Inc.
  • 3. KIOS Research and Innovation Center of Excellence, University of Cyprus
  • 4. Department of Electrical and Computer Engineering, University of Cyprus

Description

The ubiquitous integration of the IoT in current sociotechnical systems alongside the manufacturing of IoT devices and IoT-enabled services equipped with minimal security, has profoundly altered the cyber-threat landscape. Consequently, the overwhelming majority of cyberattacks utilise compromised IoT devices as a vessel for initiating large scale volumetric (e.g., DDoS) or stealthy Advanced Persistent Threats (APTs) such as ransomware through well orchestrated IoT botnets. Due to the constantly evolving nature of these botnets and their diverse structural characteristics, tracking their activities poses considerable challenges since malicious actors and botnet owners often adopt new strategies to evade detection and expand their botnet network. Evidently, Autonomous Systems (ASes) and their implied organisational and regulatory properties play a crucial role in botnet propagation. In this paper, we present a novel and extensive macroscopic measurement study quantifying ASlevel tolerance in the context of IoT botnet behavioral dynamics across the global IPv4 address space. In order to verify and justify our hypotheses in terms of AS-level tolerance we conduct a longitudinal analysis over 3.8M malicious events triggered by IoT botnets across over 8K ASes using measurements gathered through globally distributed honeypots, IP blacklists and Internet regional registries for a three year period. We argue that the findings in the herein work can greatly benefit a range of stakeholders designing, operating, and managing current defense mechanisms as well as contributing significantly towards the evolution of next generation cyber defense mechanisms. 

Notes

This version of the manuscript has been accepted for publication in the Proceedings of the 2024 IEEE International Conference on Communications (ICC 2024) after peer review (Author Accepted Manuscript). It is not the final published version (Version of Record) and does not reflect any post-acceptance improvements. The Version of Record is available online at https://doi.org/10.1109/ICC51166.2024.10622782.

Files

a894-almazarqi_accepted.pdf

Files (241.4 kB)

Name Size Download all
md5:4c79cc20b34d6c0c337875e50cb03ee3
241.4 kB Preview Download

Additional details

Funding

European Commission
COCOON – COoperative Cyber prOtectiON for modern power grids 101120221
European Commission
KIOS – KIOS Research Center of Excellence for Intelligent Systems and Networks 664639

Dates

Available
2024-08-20