Response Generation Honeypot with Anti-Detection Capabilities for IoT Botnet Lifecycle Detection

Hao Tang,Hui He,Yuming Feng,Junxiong Meng,Weizhe Zhang
DOI: https://doi.org/10.1109/tai.2024.3509812
2024-01-01
IEEE Transactions on Artificial Intelligence
Abstract:With the widespread use of edge computing, the security issues on the edge side of IoT within the cloud-edge-device architecture are becoming increasingly severe, particularly with the growing threat posed by botnets. Existing research on IoT botnet detection primarily focuses on identifying infected devices, with significantly less emphasis on detecting the botnet scanning and propagation phases. Recognizing the importance of early detection to protect devices and networks, this paper introduces RGPot-a novel honeypot based on a generative response model designed to detect the lifecycle of IoT botnets. RGPot consists of two core components: an interaction response module and a lifecycle detection module. In the Interaction Response Module, Generative Adversarial Networks (GANs) are employed to train models capable of generating responses to various types of request data. This enables RGPot to effectively simulate real IoT devices and provide tailored responses to deceive potential attackers. In the Lifecycle Detection Module, a multi-layer Long Short-Term Memory (LSTM) network is utilized to comprehensively detect the stages of an IoT botnet’s lifecycle, facilitating the precise identification of the stage at which the detected traffic data is located. To evaluate the efficacy of RGPot, we created a controlled experimental environment to assess its ability to capture IoT botnets and detect traffic data. The experimental results validate RGPot’s capability in botnet capture and anti-detection, with an accuracy of 98.81% in detecting botnet lifecycles and a reduction in false positives of approximately 5%.
What problem does this paper attempt to address?