Model-Based Framework for exploiting sensors of IoT devices using a Botnet: A case study with Android
Zubair Khaliq, Dawood Ashraf Khan, Asif Iqbal Baba, Shahbaz Ali,, Sheikh Umar Farooq

TL;DR
This paper presents a modular, communication-agnostic botnet framework for IoT devices, highlighting how sensors can be exploited maliciously and proposing privacy-preserving design considerations.
Contribution
It introduces a novel, centralized, domain fluxing-based botnet framework for IoT, demonstrating its implementation and emphasizing privacy protection during device design.
Findings
Framework is communication channel independent
Proof of concept botnet is successfully implemented
Highlights privacy risks and mitigation strategies in IoT design
Abstract
Botnets have become a serious security threat not only to the Internet but also to the devices connected to it. Factors like the exponential growth of IoT, the COVID-19 pandemic that's sweeping the planet, and the ever-larger number of cyber-criminals who now have access to or have developed increasingly more sophisticated tools are incentivizing the growth of botnets in this domain. The recent outbreak of botnets like Dark Nexus (derived from Qbot and Mirai), Mukashi, LeetHozer, Hoaxcalls, etc. shows the alarming rate at which this threat is converging. The botnets have attributes that make them an excellent platform for malicious activities in IoT devices. These IoT devices are used by organizations that need to both innovate and safeguard the personal and confidential data of their customers, employees, and business partners. The IoT devices have built-in sensors or actuators which…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · Smart Grid Security and Resilience
