English

Analyzing Endpoints in the Internet of Things Malware

Networking and Internet Architecture 2019-02-12 v1

Abstract

The lack of security measures in the Internet of Things (IoT) devices and their persistent online connectivity give adversaries an opportunity to target them or abuse them as intermediary targets for larger attacks such as distributed denial-of-service (DDoS) campaigns. In this paper, we analyze IoT malware with a focus on endpoints to understand the affinity between the dropzones and their target IP addresses, and to understand the different patterns among them. Towards this goal, we reverse-engineer 2,423 IoT malware samples to obtain IP addresses. We further augment additional information about the endpoints from Internet-wide scanners, including Shodan and Censys. We then perform a deep data-driven analysis of the dropzones and their target IP addresses and further examine the attack surface of the target device space.

Keywords

Cite

@article{arxiv.1902.03531,
  title  = {Analyzing Endpoints in the Internet of Things Malware},
  author = {Jinchun Choi and Afsah Anwar and Hisham Alasmary and Jeffrey Spaulding and DaeHun Nyang and Aziz Mohaisen},
  journal= {arXiv preprint arXiv:1902.03531},
  year   = {2019}
}

Comments

2 pages, 1 figure, Accepted as a poster for ISOC NDSS 2019

R2 v1 2026-06-23T07:36:50.105Z