2025/05/22 by Marion, Damien, Pham, Duy-Phuc, Heuser, Annelie
#Electromagnetic #IoT devices #Malware classification #deep learning #machine learning #obfuscation #rootkit detection #side-channel analysis #software-defined radio (SDR)
paper · doi:10.18464/cybin.v9i1.51
The Internet of Things (IoT) is a collection of interconnected devices, becoming increasingly complicated and suffering from inadequate security measures. They frequently employ outdated hardware and software without taking security risks into account, which makes them a target for cybercriminals, particularly those specializing in malware and rootkits. In this paper, we will present two strategies for exploiting electromagnetic side channels and address two challenges: malware classification in the presence of obfuscations and rootkit detection. Our approach focuses on IoT devices, specifically targeting ARM and MIPS architectures in Raspberry Pi and Creator CI20 devices. The framework employs advanced data preprocessing methods, allowing analysts to select a variety of machine learning and deep learning models based on their specific requirements. Our finding were published separately at (including data and codes): - ACSAC-2021: "Obfuscation Revealed: Leveraging Electromagnetic Signals for Obfuscated Malware Classification" (with an extended version presented at hardwear.io’22 USA), - RAID-2022: "ULTRA: Ultimate Rootkit Detection over the Air".