CISPA
Browse
cispa_all_2787.pdf (928.73 kB)

Detection of Threats to IoT Devices using Scalable VPN-forwarded Honeypots

Download (928.73 kB)
conference contribution
posted on 2023-11-29, 18:09 authored by Amit Tambe, Yan Lin Aung, Ragav Sridharan, Martin Ochoa, Nils Ole TippenhauerNils Ole Tippenhauer, Asaf Shabtai, Yuval Elovici
Attacks on Internet of Things (IoT) devices, exploiting inherent vulnerabilities, have intensified over the last few years. Recent large-scale attacks, such as Persirai, Hakai, etc. corroborate concerns about the security of IoT devices. In this work, we propose an approach that allows easy integration of commercial off-the-shelf IoT devices into a general honeypot architecture. Our approach projects a small number of heterogeneous IoT devices (that are physically at one location) as many (geographically distributed) devices on the Internet, using connections to commercial and private VPN services. The goal is for those devices to be discovered and exploited by attacks on the Internet, thereby revealing unknown vulnerabilities. For detection and examination of potentially malicious traffic, we devise two analysis strategies: (1) given an outbound connection from honeypot, backtrack into network traffic to detect the corresponding attack command that caused the malicious connection and use it to download malware, (2) perform live detection of unseen URLs from HTTP requests using adaptive clustering. We show that our implementation and analysis strategies are able to detect recent large-scale attacks targeting IoT devices (IoT Reaper, Hakai, etc.) with overall low cost and maintenance effort.

History

Preferred Citation

Amit Tambe, Yan Aung, Ragav Sridharan, Martin Ochoa, Nils Tippenhauer, Asaf Shabtai and Yuval Elovici. Detection of Threats to IoT Devices using Scalable VPN-forwarded Honeypots. In: ACM Conference on Data and Application Security and Privacy (CODASPY). 2019.

Primary Research Area

  • Threat Detection and Defenses

Name of Conference

ACM Conference on Data and Application Security and Privacy (CODASPY)

Legacy Posted Date

2019-01-11

Open Access Type

  • Unknown

BibTeX

@inproceedings{cispa_all_2787, title = "Detection of Threats to IoT Devices using Scalable VPN-forwarded Honeypots", author = "Tambe, Amit and Aung, Yan Lin and Sridharan, Ragav and Ochoa, Martin and Tippenhauer, Nils Ole and Shabtai, Asaf and Elovici, Yuval", booktitle="{ACM Conference on Data and Application Security and Privacy (CODASPY)}", year="2019", }

Usage metrics

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC