Published June 27, 2023 | Version v1
Preprint Open

Metasoma: Decentralized and Collaborative Early-Stage Detection of IoT Botnets

  • 1. KTH Royal Institute of Technology
  • 2. Università degli Studi dell'Insubria

Description

Early-stage detection of botnets during their spreading phase, before any attack, is fundamental to IoT security. Recently introduced lightweight memory networks represent the state of the art in this domain. However, they require a central system to capture and analyze all traffic in the network, which may not always be feasible in real-world scenarios. In this paper, we introduce a decentralized and collaborative alternative, in which the IoT devices themselves are responsible for this task without any central observer or coordinator. Our results show that the performance of this novel approach is competitive with similar centralized solutions, despite the lack of a global view of the network at any participating device. We also provide an extensive analysis of the security limitations of our fully-decentralized detection system. We identify the potential exploits that an attacker may attempt to perform, assess their impact on the IoT network as well as propose and evaluate effective countermeasures.

Files

FULLTEXT01.pdf

Files (322.1 kB)

Name Size Download all
md5:066a4e6abaa7c1df00bb592b89e1edb5
322.1 kB Preview Download

Additional details

Funding

European Commission
RAIS – RAIS: Real-time Analytics for the Internet of Sports 813162