Creation of a Dataset Modeling the Behavior of Malware Affecting the Confidentiality of Data Managed by IoT Devices

Published in Studies in Computational Intelligence, 2022

Internet-of-Things (IoT) platforms are vulnerable to cyberattacks due to their exposition to the internet and the resource-constrained capabilities of their devices. Cyberattacks can be conducted by different malware families, being spyware and backdoor, two of the most relevant due to their impact on data handled by IoT devices. Traditional detection systems based on signatures are unsuitable for zero-day attacks. Therefore, the current trend is to apply machine and deep learning to detect anomalies in the device behavior. However, there is a lack of datasets containing clean and infected behavioral data to train models. Most of the existing datasets do not consider resource-constrained devices, the malware samples are obsolete, and they do not monitor device behaviors. Thus, this work presents FabIoT, a dataset modeling the behavior of a resource-constrained device while being infected by three real backdoors exhibiting heterogeneous attack behaviors. The monitored device is a Raspberry Pi 3, acting as a spectrum sensor of a crowdsensing platform called ElectroSense. The dataset contains several hours of behavioral data sources such as CPU, I/O, Network, Memory, or Scheduler. Statistical analysis of the collected data demonstrated the suitability of the dataset to detect normal and under-attack behaviors.

Recommended citation: Huertas Celdrán, Alberto, Sánchez Sánchez, Pedro Miguel, Sisi, Fabio, Bovet, Gérôme, Martínez Pérez, Gregorio, & Stiller, Burkhard. (2022). "Creation of a Dataset Modeling the Behavior of Malware Affecting the Confidentiality of Data Managed by IoT Devices." Studies in Computational Intelligence.
Download Paper