{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T07:14:54Z","timestamp":1772781294958,"version":"3.50.1"},"reference-count":40,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2021,12,23]],"date-time":"2021-12-23T00:00:00Z","timestamp":1640217600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>The leaked IoT botnet source-codes have facilitated the proliferation of different IoT botnet variants, some of which are equipped with new capabilities and may be difficult to detect. Despite the availability of solutions for automated analysis of IoT botnet samples, the identification of new variants is still very challenging because the analysis results must be manually interpreted by malware analysts. To overcome this challenge, we propose an approach for automated behaviour-based clustering of IoT botnet samples, aimed to enable automatic identification of IoT botnet variants equipped with new capabilities. In the proposed approach, the behaviour of the IoT botnet samples is captured using a sandbox and represented as behaviour profiles describing the actions performed by the samples. The behaviour profiles are vectorised using TF-IDF and clustered using the DBSCAN algorithm. The proposed approach was evaluated using a collection of samples captured from IoT botnets propagating on the Internet. The evaluation shows that the proposed approach enables accurate automatic identification of IoT botnet variants equipped with new capabilities, which will help security researchers to investigate the new capabilities, and to apply the investigation findings for improving the solutions for detecting and preventing IoT botnet infections.<\/jats:p>","DOI":"10.3390\/fi14010006","type":"journal-article","created":{"date-parts":[[2021,12,23]],"date-time":"2021-12-23T10:16:18Z","timestamp":1640254578000},"page":"6","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["An Automated Behaviour-Based Clustering of IoT Botnets"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4552-2297","authenticated-orcid":false,"given":"Tolijan","family":"Trajanovski","sequence":"first","affiliation":[{"name":"School of Computer Science, University of Manchester, Kilburn Building, Manchester M13 9PL, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ning","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Manchester, Kilburn Building, Manchester M13 9PL, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,12,23]]},"reference":[{"key":"ref_1","first-page":"1","article-title":"Tracking Mirai variants","volume":"10","author":"Liu","year":"2018","journal-title":"Virus Bull."},{"key":"ref_2","unstructured":"Paquet-Clouston, M., Bilodeau, O., and GoSecure Inc. (2021, December 19). Attacking Linux\/Moose 2.0 Unraveled an Ego Market. Available online: https:\/\/www.botconf.eu\/wp-content\/uploads\/2016\/11\/PR08-MOOSE-BILODEAU-PAQUET-CLOUSTON.pdf."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","article-title":"N-BaIoT\u2014Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders","volume":"17","author":"Elovici","year":"2018","journal-title":"IEEE Pervasive Comput."},{"key":"ref_4","unstructured":"Secplicity (2021, December 19). IoT Botnets Are Evolving\u2014How Big Can They Get?. Available online: https:\/\/www.secplicity.org\/2018\/02\/20\/iot-botnets-evolving-big-can-get\/."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1109\/MC.2017.201","article-title":"DDoS in the IoT: Mirai and Other Botnets","volume":"50","author":"Kolias","year":"2017","journal-title":"Computer"},{"key":"ref_6","first-page":"54","article-title":"Understanding the Mirai Botnet","volume":"317","author":"Antonakakis","year":"2017","journal-title":"Usenix Secur."},{"key":"ref_7","unstructured":"McAfee (2021, December 19). McAffee Labs Threat Report 06.21. Available online: https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-threats-jun-2021.pdf."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"124360","DOI":"10.1109\/ACCESS.2021.3110188","article-title":"An Automated and Comprehensive Framework for IoT Botnet Detection and Analysis (IoT-BDA)","volume":"9","author":"Trajanovski","year":"2021","journal-title":"IEEE Access"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Cozzi, E., Graziano, M., Fratantonio, Y., and Balzarotti, D. (2018, January 20\u201324). Understanding Linux Malware. Proceedings of the 2018 IEEE Symposium on Security and Privacy (SP), Francisco, CA, USA.","DOI":"10.1109\/SP.2018.00054"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"145768","DOI":"10.1109\/ACCESS.2020.3014891","article-title":"V-Sandbox for Dynamic Analysis IoT Botnet","volume":"8","author":"Le","year":"2020","journal-title":"IEEE Access"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1165","DOI":"10.1109\/TNSM.2021.3075315","article-title":"A Multi-Dimensional Deep Learning Framework for IoT Malware Classification and Family Attribution","volume":"18","author":"Dib","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Kawasoe, R., Han, C., Isawa, R., Takahashi, T., and Takeuchi, J. (2021, January 22\u201326). Investigating behavioral differences between IoT malware via function call sequence graphs. Proceedings of the ACM Symposium on Applied Computing, Virtual Event.","DOI":"10.1145\/3412841.3442041"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1109\/LNET.2021.3076600","article-title":"A Strings-Based Similarity Analysis Approach for Characterizing IoT Malware and Inferring Their Underlying Relationships","volume":"3","author":"Torabi","year":"2021","journal-title":"IEEE Netw. Lett."},{"key":"ref_14","first-page":"766","article-title":"A Fast Algorithm for Constructing Phylogenetic Trees with Application to IoT Malware Clustering","volume":"Volume 11953","author":"He","year":"2019","journal-title":"Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Bak, M., Papp, D., Tamas, C., and Buttyan, L. (2020, January 20\u201324). Clustering IoT Malware based on Binary Similarity. Proceedings of the IEEE\/IFIP Network Operations and Management Symposium 2020: Management in the Age of Softwarization and Artificial Intelligence, NOMS 2020, Budapest, Hungary.","DOI":"10.1109\/NOMS47738.2020.9110432"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"267","DOI":"10.1016\/j.future.2020.04.031","article-title":"Characterizing Linux-based malware: Findings and recent trends","volume":"110","year":"2020","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_17","first-page":"25","article-title":"Text Mining: Use of TF-IDF to Examine the Relevance of Words to Documents","volume":"181","author":"Qaiser","year":"2018","journal-title":"Int. J. Comput. Appl."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3068335","article-title":"DBSCAN Revisited","volume":"42","author":"Schubert","year":"2017","journal-title":"ACM Trans. Database Syst."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Margolis, J., Oh, T.T., Jadhav, S., Kim, Y.H., and Kim, J.N. (2017, January 24\u201325). An In-Depth Analysis of the Mirai Botnet. Proceedings of the 2017 International Conference on Software Security and Assurance (ICSSA), Altoona, PA, USA.","DOI":"10.1109\/ICSSA.2017.12"},{"key":"ref_20","unstructured":"Unit42-Palo Alto Networks (2021, December 19). Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices. Available online: https:\/\/unit42.paloaltonetworks.com\/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices\/."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Sicato, J.C.S., Sharma, P.K., Loia, V., and Park, J.H. (2019). Vpnfilter malware analysis on cyber threat in smart home network. Appl. Sci., 9.","DOI":"10.3390\/app9132763"},{"key":"ref_22","unstructured":"Skuratovich, S. (2018). Defeating Sandbox Evasion: How to Increase Successful Emulation Rate in Your Virtualized Environment. Virus Bull., 1\u20135. Available online: https:\/\/blog.checkpoint.com\/wp-content\/uploads\/2016\/10\/DefeatingSandBoxEvasion-VB2016_CheckPoint.pdf."},{"key":"ref_23","unstructured":"Abuse.ch (2021, December 19). IoT Botnets Takedown Statistics. Available online: https:\/\/urlhaus.abuse.ch\/statistics\/#avg_takedown."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Hoang, D.K., Tho Nguyen, D., and Vu, D.L. (2020, January 6\u20137). IoT Malware Classification Based on System Calls. Proceedings of the 2020 RIVF International Conference on Computing and Communication Technologies, RIVF 2020, Ho Chi Minh, Vietnam.","DOI":"10.1109\/RIVF48685.2020.9140763"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Cozzi, E., Vervier, P.A., Dell\u2019Amico, M., Shen, Y., Bilge, L., and Balzarotti, D. (2020). The Tangled Genealogy of IoT Malware. Annual Computer Security Applications Conference, ACM.","DOI":"10.1145\/3427228.3427256"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Lingenfelter, B., Vakilinia, I., and Sengupta, S. (2020, January 6\u20138). Analyzing Variation among IoT Botnets Using Medium Interaction Honeypots. Proceedings of the 2020 10th Annual Computing and Communication Workshop and Conference, CCWC 2020, Las Vegas, NV, USA.","DOI":"10.1109\/CCWC47524.2020.9031234"},{"key":"ref_27","unstructured":"(2009). Bayer, Ulrich and Comparetti, Paolo and Hlauschek, Clemens and Kr\u00fcgel, Christopher and Kirda, E. Scalable, Behavior-Based Malware Clustering. NDSS, 9, 8\u201311."},{"key":"ref_28","unstructured":"URLhaus (2021, December 19). Top Malware Hosting Networks. Available online: https:\/\/urlhaus.abuse.ch\/statistics\/."},{"key":"ref_29","unstructured":"(2021, December 19). SystemTap. Available online: https:\/\/sourceware.org\/systemtap\/."},{"key":"ref_30","unstructured":"(2021, December 19). Strace. Available online: https:\/\/man7.org\/linux\/man-pages\/man1\/strace.1.html."},{"key":"ref_31","unstructured":"(2021, December 19). TCPDump. Available online: https:\/\/www.tcpdump.org\/manpages\/tcpdump.1.html."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1017\/S1351324916000334","article-title":"Emerging Trends: Word2Vec","volume":"23","author":"Church","year":"2017","journal-title":"Nat. Lang. Eng."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"835","DOI":"10.1007\/s11192-020-03583-6","article-title":"Using neural-network based paragraph embeddings for the calculation of within and between document similarities","volume":"125","author":"Thijs","year":"2020","journal-title":"Scientometrics"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"De Boom, C., Van Canneyt, S., Bohez, S., Demeester, T., and Dhoedt, B. (2015, January 14\u201317). Learning Semantic Similarity for Very Short Texts. Proceedings of the 15th IEEE International Conference on Data Mining Workshop, ICDMW 2015, Atlantic, NJ, USA.","DOI":"10.1109\/ICDMW.2015.86"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"348","DOI":"10.3102\/1076998619832248","article-title":"Machine Learning Made Easy: A Review of Scikit-learn Package in Python Programming Language","volume":"44","author":"Hao","year":"2019","journal-title":"J. Educ. Behav. Stat."},{"key":"ref_36","unstructured":"Angrishi, K. (2017). Turning Internet of Things(IoT) into Internet of Vulnerabilities (IoV): IoT Botnets. arXiv."},{"key":"ref_37","unstructured":"Scikit-Learn (2021, December 19). Mean-Shift Clustering Algorithm. Available online: https:\/\/scikit-learn.org\/stable\/modules\/generated\/sklearn.cluster.MeanShift.html."},{"key":"ref_38","unstructured":"Scikit-Learn (2021, December 19). Agglomerative Clustering Algorithm. Available online: https:\/\/scikit-learn.org\/stable\/modules\/generated\/sklearn.cluster.AgglomerativeClustering.html."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Monrose, F., Dacier, M., Blanc, G., and Garcia-Alfaro, J. (2016). AVclass: A Tool for Massive Malware Labeling. Research in Attacks, Intrusions, and Defenses, Springer International Publishing.","DOI":"10.1007\/978-3-319-45719-2"},{"key":"ref_40","unstructured":"(2021, December 19). Virustotal. Available online: https:\/\/virustotal.com."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/1\/6\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:51:45Z","timestamp":1760169105000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/1\/6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,23]]},"references-count":40,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2022,1]]}},"alternative-id":["fi14010006"],"URL":"https:\/\/doi.org\/10.3390\/fi14010006","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,12,23]]}}}