A Lightweight Moving Target Defense Framework for Multi-purpose Malware Affecting IoT Devices

10/14/2022
by   Jan von der Assen, et al.
0

Malware affecting Internet of Things (IoT) devices is rapidly growing due to the relevance of this paradigm in real-world scenarios. Specialized literature has also detected a trend towards multi-purpose malware able to execute different malicious actions such as remote control, data leakage, encryption, or code hiding, among others. Protecting IoT devices against this kind of malware is challenging due to their well-known vulnerabilities and limitation in terms of CPU, memory, and storage. To improve it, the moving target defense (MTD) paradigm was proposed a decade ago and has shown promising results, but there is a lack of IoT MTD solutions dealing with multi-purpose malware. Thus, this work proposes four MTD mechanisms changing IoT devices' network, data, and runtime environment to mitigate multi-purpose malware. Furthermore, it presents a lightweight and IoT-oriented MTD framework to decide what, when, and how the MTD mechanisms are deployed. Finally, the efficiency and effectiveness of the framework and MTD mechanisms are evaluated in a real-world scenario with one IoT spectrum sensor affected by multi-purpose malware.

READ FULL TEXT
research
08/11/2023

CyberForce: A Federated Reinforcement Learning Framework for Malware Mitigation

The expansion of the Internet-of-Things (IoT) paradigm is inevitable, bu...
research
06/27/2023

MTFS: a Moving Target Defense-Enabled File System for Malware Mitigation

Ransomware has remained one of the most notorious threats in the cyberse...
research
12/30/2022

RL and Fingerprinting to Select Moving Target Defense Mechanisms for Zero-day Attacks in IoT

Cybercriminals are moving towards zero-day attacks affecting resource-co...
research
11/03/2022

LE3D: A Lightweight Ensemble Framework of Data Drift Detectors for Resource-Constrained Devices

Data integrity becomes paramount as the number of Internet of Things (Io...
research
01/29/2019

Malicious cryptocurrency miners: Status and Outlook

In this study, we examine the behavior and profitability of modern malwa...
research
08/07/2022

IoT-REX: A Secure Remote-Control System for IoT Devices from Centralized Multi-Designated Verifier Signatures

IoT technology has been developing rapidly, while at the same time, it r...
research
01/18/2023

Relativistic Digital Twin: Bringing the IoT to the Future

Complex IoT ecosystems often require the usage of Digital Twins (DTs) of...

Please sign up or login with your details

Forgot password? Click here to reset