20212021 International Conference on Computational Science and Computational Intelligence (CSCI)Requires access

Mozi IoT Malware and Its Botnets: From Theory To Real-World Observations

Josh Sahota, Natalija Vlajic

Open publisher page 11 citations

Abstract

Mozi IoT malware arrived on the Internet stage in late 2019, and since then has managed to infected over 1.5 million IoT devices, established numerous large-scale botnets, and generate more attack traffic in 2020 and 2021 than any of its IoT-malware counterparts. Even though Mozi code is a blend of three other infamous malware families (Mirai, Gafgyt, and IoTReaper), the main distinguishing feature of Mozi botnets -relative to those of its direct predecessors - is their P2P networking architecture. Notwithstanding Mozi’s significance and prevalence in the real world, there is very little mention of this IoT malware in academic research literature. This paper is one of the first attempts to bring the attention of the research community to the architecture and operation of Mozi and its botnets. The information provided in the paper is in part based on our own experimentation with live monitored instances of Mozi malware.

About this research paper

What this paper is about

Mozi IoT malware arrived on the Internet stage in late 2019, and since then has managed to infected over 1.5 million IoT devices, established numerous large-scale botnets, and generate more attack traffic in 2020 and 2021 than any of its IoT-malware counterparts. Even though Mozi code is a blend of three other infamous malware families (Mirai, Gafgyt, and IoTReaper), the main distinguishing feature of Mozi botnets -relative to those of its direct predecessors - is their P2P networking architecture. Notwithstanding Mozi’s significance and prevalence in the real world, there is very little mention of this IoT malware in academic research literature. This paper is one of the first attempts to bring the attention of the research community to the architecture and operation of Mozi and its botnets. The information provided in the paper is in part based on our own experimentation with live monitored instances of Mozi malware.

Why it matters

OpenAlex reports 11 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Mozi IoT malware arrived on the Internet stage in late 2019, and since then has managed to infected over 1.5 million IoT devices, established numerous large-scale botnets, and generate more attack traffic in 2020 and 2021 than any of its IoT-malware counterparts. Even though Mozi code is a blend of three other infamous malware families (Mirai, Gafgyt, and IoTReaper), the main distinguishing feature of Mozi botnets -relative to those of its direct predecessors - is their P2P networking architecture. Notwithstanding Mozi’s significance and prevalence in the real world, there is very little mention of this IoT malware in academic research literature. This paper is one of the first attempts to bring the attention of the research community to the architecture and operation of Mozi and its botnets. The information provided in the paper is in part based on our own experimentation with live monitored instances of Mozi malware.

Key concepts: Botnet, Malware, Computer security, Computer science, Internet of Things, World Wide Web, The Internet

Related papers

Back to paper searchBrowse research topicsOriginal source
Mozi IoT Malware and Its Botnets: From Theory To Real-World Observations — Research Paper | ScholarLens