Source-linked AI summary
Turning Internet of Things(IoT) into Internet of Vulnerabilities (IoV) : IoT Botnets
Kishore Angrishi
TL;DR
IoT botnets expose publicly accessible devices whose security is often an afterthought, creating cyber risks and enabling large-scale DDoS attacks. The paper examines botnet anatomy, operating modes, incidents, vulnerabilities, mitigations, and cyber insurance, concluding that IoT-related DDoS risks are growing and require risk-management measures.
Problem
Many IoT devices are publicly accessible and poorly secured, turning connected devices into vulnerabilities that cyber criminals can exploit.
Method
The paper analyzes IoT botnet structure and operation using released LightAidra/Aidra, BASHLITE, and Mirai source code, reverse engineering, incident analysis, and mitigation recommendations.
Results
DDoS attack capacity increased from 100 Mbps in 2002 to 1.1-1.5Tbps in 2016, while IoT botnet source-code availability contributed to further malicious use.
Takeaways & Limitations
Device manufacturers and end-users should consider security controls and cyber insurance to manage risks to vital assets from IoT-botnet incidents.
Abstract
from arXiv · showhide
Internet of Things (IoT) is the next big evolutionary step in the world of internet. The main intention behind the IoT is to enable safer living and risk mitigation on different levels of life. With the advent of IoT botnets, the view towards IoT devices has changed from enabler of enhanced living into Internet of vulnerabilities for cyber criminals. IoT botnets has exposed two different glaring issues, 1) A large number of IoT devices are accessible over public Internet. 2) Security (if considered at all) is often an afterthought in the architecture of many wide spread IoT devices. In this article, we briefly outline the anatomy of the IoT botnets and their basic mode of operations. Some of the major DDoS incidents using IoT botnets in recent times along with the corresponding exploited vulnerabilities will be discussed. We also provide remedies and recommendations to mitigate IoT related cyber risks and briefly illustrate the importance of cyber insurance in the modern connected world.
I. INTRODUCTION
IoT connects specialized computer-like devices across private networks and the public Internet, but weak security and complex network infrastructure expose them to cyber risks and DDoS mitigation challenges.
- I. INTRODUCTION: IoT devices are specialized computers, such as smartphones and refrigerators, connected through private networks or the public Internet.The paper emphasizes that these devices often use powerful microprocessors and perform specialized jobs.
- I. INTRODUCTION: Poor or absent security in IoT devices adds more than 9 billion potentially insecure devices to an already complex Internet.The paper identifies device security as a central distinction between IoT devices and conventional specialized equipment.
- II. INTRODUCTION TO SIMPLIFIED INTERNET: The Internet comprises access and core networks, with IoT devices mainly deployed at access-network edges where botnets exploit interface vulnerabilities.The discussion focuses on DSL access networks and the TCP/IP suite to explain these vulnerabilities.
- II. INTRODUCTION TO SIMPLIFIED INTERNET: DSL modems, often integrated into home routers, connect customer premises to ISP infrastructure and blur the boundary between home and provider networks.BRAS provides connectivity, policy management, routing, and client network parameters within the ISP architecture.
- II. INTRODUCTION TO SIMPLIFIED INTERNET: ISP infrastructure uses authentication, remote modem management, DNS resolution, time synchronization, and DHCP address assignment to support DSL connectivity.These functions are provided through dedicated ISP systems connected to the BRAS.
- II. INTRODUCTION TO SIMPLIFIED INTERNET: CDNs, DNS providers, and ISPs offer Anti-DDoS services by filtering, absorbing, or redistributing malicious traffic floods.CDNs also cache bandwidth-intensive website content near end users to reduce load on origin servers and speed delivery.
A. Protocols
The paper presents TCP/IP as a widely used four-layer abstraction that separates communication protocols from physical media and organizes sender–receiver data exchange.
- A. Protocols: TCP/IP is a four-layer architecture that abstracts communication from physical media such as copper, fiber, and mobile networks.The paper contrasts TCP/IP with the seven-layer OSI architecture and restricts its discussion to TCP/IP.
- A. Protocols: Each TCP/IP layer communicates abstractly with the layer above, less abstractly with the layer below, and virtually with its peer layer.These interactions allow each layer to add activity while preserving a logical communication path between endpoints.
- A. Protocols: Data communication proceeds logically from layer 4 toward layer 1 before traversing the communication medium between sender and receiver.Figure 5 illustrates this layered communication using UDP as the transport-layer protocol.
III. DDOS ATTACKS AND IOT BOTNETS
IoT botnets turn insecure, Internet-connected devices into distributed platforms for DDoS attacks that exhaust victim resources and employ increasingly varied traffic and techniques.
- DDoS attacks: DDoS botnets enslave Internet-enabled devices, which simultaneously request services until servers overwhelm and ignore legitimate users.The attacks can pursue financial gain, revenge, extortion, or activism.
- Attack techniques: 64% of DDoS attacks observed between 1 April and 30 June 2016 employed multiple attack types, complicating identification of the attackers’ true intention.Layered attacks may disrupt operations, probe defenses, or distract victims during another attack vector.
- IoT botnets: IoT devices are difficult to remediate because they commonly have constrained memory, flash storage, processing architectures, and weak or absent security.The paper identifies ARM and MIPS architectures, ELF binaries, limited memory, and limited flash capacity among relevant characteristics.
- IoT botnets: IoT malware often remains unobtrusive, resides in temporary memory, activates on bot herder commands, and avoids reflection or amplification techniques.Avoiding conventional techniques makes these attacks more difficult to recognize and mitigate using conventional methods.
- DDoS attacks: IoT botnet traffic floods commonly reach 100 Gbps or higher, exceeding the volume associated with conventional PC botnets.These floods can exhaust bandwidth or server resources, causing unavailability or undesirable server states.
- Attack techniques: IoT botnets use HTTP, TCP, UDP, GRE, and DNS water torture traffic, with devices distributed around the world.DNS water torture uses randomly prefixed queries to make recursive DNS servers query an authoritative DNS server, requiring relatively few bot queries.
A. Evolution of IoT Malware
IoT malware evolved from early IRC botnets and worms using brute-force credentials or known vulnerabilities into diverse, architecture-aware families capable of large-scale DDoS attacks.
- Early malware: Linux/Hydra, released in 2008, is described as the earliest known IoT-targeting malware and includes both spreading and DDoS functionality.The framework was open source and designed for extensibility.
- Early malware: Early malware such as Psyb0t, Chuck Noris, Tsunami, and LightAidra used IRC control, brute-force access, authentication bypass, DNS manipulation, or scanning for exposed Telnet ports.Psyb0t used predefined lists of 6000 usernames and 13000 passwords.
- Early malware: Carna infected routers with empty or default credentials to measure Internet extent, while Linux.Darlloz exploited an old PHP vulnerability and then blocked Telnet access.Carna also scanned for and attempted to remove LightAidra from infected devices.
- Malware families: Linux.Wifatch infects devices with weak or default credentials, removes other malware, disables Telnet, and updates through a peer-to-peer network.It also deletes malware remnants from infected devices.
- Malware families: TheMoon targets Linksys routers through command execution in a POST parameter, while Spike/Dofloo targets Windows, Linux, MIPS, ARM, and IoT systems.Akamai observed one Spike/Dofloo attack peaking at 215 Gbps.
- Malware families: BASHLITE, Remaiten, and Mirai expanded IoT botnet capabilities through credential brute forcing, architecture adaptation, and high-volume multi-vector attacks.BASHLITE reportedly enslaved over 1 million devices and reached 400 Gbps; Mirai infected 4000 devices per hour and powered a 1.1 Tbps attack involving 148000 devices.
- Malware families: Mirai infections rose from 213000 to 483000 in two weeks, spanning more than 164 countries and generating GRE, SYN, ACK, STOMP, DNS, UDP, and HTTP floods.Linux/IRCTelnet combined Tsunami’s IRC, BASHLITE’s Telnet brute force and code injection, and Mirai’s credential list for IPv4 and IPv6 attacks.
B. DDoS-as-a-Service
DDoS-as-a-Service makes large-scale attacks commercially accessible, with IoT-driven attacks contributing to the growth of high-volume DDoS activity and underground attack markets.
- DDoS-as-a-Service: 138% increase in DDoS attacks exceeding 100 Gbps was observed in Q3 2016 compared with 2015, attributed to IoT usage and commercial DDoS services.A 5–6 Gbps attack lasting at least 10 minutes could reportedly be ordered anonymously for $6.
- DDoS-as-a-Service: More than 435 booter and stresser websites operated on the open Internet, with additional DDoS-as-a-Service offers available on the Darknet.Darknet marketplaces offered one-click access to DDoS services, tools, and personally identifiable information lists.
- Commercial attack tools: Shenron offered a $19.99 package for a 35 Gbps UDP/TCP attack lasting 20 minutes.
- Commercial attack tools: vDOS offered a $19.99 package providing access to a shared network capable of a 216 Gbps attack across thirteen attack vectors.Akamai observed DDoS-as-a-Service traffic accounting for a large portion of attack traffic in major attacks.
C. Recent Famous DDoS Incidents by IoT Botnets
A September 2016 attack on Brian Krebs’s blog used compromised IoT devices and reached 623 Gbps, reportedly as retaliation for reporting on a DDoS-as-a-Service provider.
- Recent famous incidents: 623 Gbps DDoS attack targeted security researcher Brian Krebs’s blog on 30 September 2016 and involved many compromised IoT devices.The attack was considered retaliation for articles about the takedown of the vDOS provider.
1) KrebsOnSecurity.com:
IoT botnets enabled exceptionally large DDoS attacks against KrebsOnSecurity.com, OVH, and Dyn, disrupting services and exposing the consequences of Internet-accessible, poorly secured devices.
- 1) KrebsOnSecurity.com:: 623 Gbps from 24,000 IoT devices disrupted KrebsOnSecurity.com and exceeded Akamai’s mitigation capacity.The devices were primarily Internet-exposed DVRs and IP cameras infected with Mirai and BASHLITE.
- 1) KrebsOnSecurity.com:: 1.1 Tbps to 1.5 Tbps from 145,607 cameras and DVRs made OVH’s attack the largest reported DDoS attack at that time.Each device generated between 1–30 Mbps, with traffic suspected to originate from Mirai- and BASHLITE-infected devices.
- 1) KrebsOnSecurity.com:: 100,000 Internet-enabled IoT devices participated in the Dyn attack, which affected its managed DNS service.The attack involved devices including printers, IP cameras, residential gateways, and baby monitors, with Mirai identified as the primary malware.
- 1) KrebsOnSecurity.com:: Dyn’s outage made websites including Airbnb, Amazon.com, Reddit, and Spotify partly or completely unavailable across large areas of Europe and North America.Recursive DNS retries subsequently generated 10–20 times the typical legitimate traffic to Dyn’s DNS servers.
- 1) KrebsOnSecurity.com:: Dyn’s managed-DNS market presence fell from 137 to 90 of the top 1,000 Alexa websites after the attack, according to Datanyze.The passage attributes customer losses to competitors Cloudflare DNS and Amazon Route 53.
- 1) KrebsOnSecurity.com:: The Dyn attack’s motivation remained unclear, although it triggered broader cybersecurity and legislative discussion about IoT botnets and DDoS attacks.The passage states that claims about a possible connection to BackConnect lacked conclusive evidence.
4) Deutsche Telekom:
The Deutsche Telekom incident illustrates how Mirai variants exploited exposed remote-management interfaces and command injection flaws in home routers, affecting a large customer population.
- 4) Deutsche Telekom:: The affected Speedport manufacturer Arcadyan appeared unrelated to Zyxel, which produced a vulnerable modem used by ISP Eir.This indicates that similar Mirai exploitation affected devices from different manufacturers and providers.
- 4) Deutsche Telekom:: Mirai variants exploited three vulnerabilities, including Internet-exposed port 7547 and weak or missing authentication for TR-069 remote management.The passage also describes insecure authentication over unencrypted paths or improperly implemented certificate authentication.
- 4) Deutsche Telekom:: A Mirai variant continuously scanning the Internet could find newly connected vulnerable routers or modems within 10 minutes.A simple power reset could remove the malware because it resided in device RAM, but repeated scanning exposed newly connected devices again.
- 4) Deutsche Telekom:: Tests found 48 vulnerable devices in use, while some Speedport modems became slow or nonfunctional under moderate load even without confirmed infection.The observed behavior suggests that attempted exploitation could still cause device crashes or instability.
3) Lappeenranta, Finland:
The paper surveys additional IoT-botnet incidents involving financial institutions, election-related services, communications, and building automation, while noting uncertainty around some reported effects.
- 3) Lappeenranta, Finland:: 24,000 IoT devices distributed across approximately 30 countries targeted at least five Russian banks in prolonged DDoS attacks during November 2016.The targeted institutions included Sberbank, Alfa Bank, the Moscow Exchange, the Bank of Moscow, and Rosbank.
- 3) Lappeenranta, Finland:: Three 30-second Mirai HTTP application-layer attacks targeted Donald Trump’s campaign website and, in one instance, Hillary Clinton’s site, without reported outages.Flashpoint believed the incidents may have been carried out by a Mirai user testing the botnet.
- 3) Lappeenranta, Finland:: A separate attack saturated all four 1 Gbps connections of election phone-bank service TCN and continued for 24 hours.The attacker progressively increased the flood while varying source IP addresses and traffic types.
- 3) Lappeenranta, Finland:: Wikileaks email publication servers were knocked offline for nearly 24 hours by an allegedly politically motivated DDoS attack.The passage connects the alleged response to the release of emails from John Podesta’s compromised account.
E. Anatomy of IoT Botnets
IoT botnets combine scanning, loading, malware distribution, command-and-control, reporting, and attacking functions, often exploiting exposed services and default credentials. The paper recommends technical, organizational, regulatory, and insurance measures to reduce these risks.
- Botnet components: IoT botnets typically include bots, C2 servers, scanners, reporting servers, loaders, and malware distribution servers, although functions may be combined.Mirai, for example, has bots scan for vulnerable devices while also performing DDoS attacks.
- Infection workflow: Botnets continuously scan Internet-facing IoT devices, identify vulnerable systems, and report addresses and credentials for subsequent compromise.Scanners may be external, bot-based, or C2-operated, with Shodan and Censys helping locate potential victims.
- Infection workflow: Loaders access vulnerable devices through Telnet or web interfaces, commonly using unchanged default credentials to install malware.Default passwords are described as the first access point for many IoT malware infections.
- Botnet operation: After infection, malware may escalate privileges, block competing access, reconfigure the device, contact its C2, and remain dormant until ordered to launch DDoS attacks.The documented sequence includes securing the device against other malware and maintaining regular C2 communication.
- Underlying vulnerabilities: IoT security weaknesses persist because manufacturers prioritize rapid, inexpensive production, provide limited patching, and sometimes hard-code default credentials.The paper reports that HP found 70% of IoT devices vulnerable and notes that device lifetimes can extend for decades.
- Remediation and recommendations: Recommended mitigations include limiting communications, using unique strong passwords, requiring update checks, accountability laws, certification, incident plans, and cyber insurance.The recommendations address manufacturers, ISPs, commercial organizations, and end users.
A. Best Practices
The paper presents layered prevention and recovery practices for IoT malware, emphasizing network isolation, credential changes, patching, service reduction, monitoring, and user awareness.
- Recovery: After infection, users should disconnect and reboot the device, change default credentials, update firmware, and then reconnect it.The reboot recommendation relies on malware commonly residing in temporary memory.
- Prevention: Preventive practices include changing default passwords, applying manufacturer patches promptly, disabling unused services, and disabling Universal Plug and Play unless necessary.These steps target common access and exposure paths used by IoT malware.
- Prevention: End users should isolate IoT devices on protected networks and prevent unnecessary Internet access.Firewalls and network segmentation are suggested as isolation mechanisms.
- Prevention: Users should choose manufacturers with security track records and regularly monitor firewall logs for suspicious Telnet traffic.The paper specifically identifies ports 2323 and 23/TCP for monitoring.
- User awareness: Users should understand the capabilities and applications of their installed IoT devices.The paper frames user awareness as part of protection against IoT malware.
B. Cyber insurance
Cyber insurance is presented as one component of IoT risk management involving attackers, manufacturers, consumers, targets, service providers, and insurers. Coverage can support incident response, but exclusions and provider trust constrain its protection.
- Actors and relationships: A cyber incident involves attackers, device manufacturers, consumers, targets, IT service providers, and insurance companies.The paper depicts relationships among these actors and emphasizes cooperation between insurers and IT service providers.
- Actors and relationships: Insurers can use IT-provider risk assessments to shape coverage, while providers deliver crisis management, forensics, data recovery, and system hardening after incidents.The paper states that insurance coverage can make these services faster and more reliable for targets.
- Limitations: Cyber insurance excludes some losses, including bodily or physical injury, product recalls, and certain damages involving property containing defective products.The exclusions distinguish first-party and third-party coverage categories.
- Limitations: Cyber insurance cannot cover every cyber-related loss, including some business effects caused by outages of external networks.Examples include failures involving power, telecommunications, or Internet infrastructure.
- Coverage: Consumers and DDoS targets can receive coverage for many non-damage costs, including consulting, notification, legal, public-relations, and forensic IT services.The listed costs include crisis management, call centers, credit monitoring, claims handling, and data forensics.
- Coverage: Device manufacturers may need technology E&O, product liability, and product recall insurance for distinct third-party and first-party exposures.The paper gives recalled DVRs with hardcoded credentials as an example of product-related risk.
V. CONCLUSIONS
IoT botnets have increased the scale and accessibility of DDoS attacks while exposing weak device security and user practices. The paper concludes that insurance and other insurance lines can help manufacturers and users manage these cyber risks.
- V. CONCLUSIONS: In 2016, the largest DDoS attacks reached approximately 1.1–1.5 Tbps, compared with 100 Mbps in 2002.The paper links this growth with freely available IoT botnet source code and large-scale attacks involving Mirai.
- V. CONCLUSIONS: The paper identifies IoT botnets as evidence of basic security deficiencies in IoT devices and insufficient adherence to user best practices.It presents these weaknesses alongside the increasing scale of DDoS attacks.
- V. CONCLUSIONS: Device manufacturers and end users should consider cyber insurance or other insurance lines to manage and reduce risks to vital assets.The recommendation particularly highlights additional insurance needs for device manufacturers.