(2) Ahmad Zamsuri
(3) Yuhelmi Yuhelmi
(4) Muhamad Sadar
*corresponding author
AbstractThe rapid proliferation of Internet of Things (IoT) devices has introduced significant security gaps, making them prime targets for large-scale botnet infiltrations. Among these threats, the Mozi botnet has emerged as a formidable challenge due to its decentralized peer-to-peer (P2P) structure and its ability to exploit weak credentials and unpatched vulnerabilities. This study conducts a comprehensive vulnerability assessment and proposes strategic mitigation frameworks to counter Mozi botnet attacks. Using a laboratory-controlled environment, we simulated Mozi’s propagation vectors, specifically focusing on its exploitation of Telnet brute-forcing and command injection vulnerabilities. The assessment identifies critical weaknesses in IoT firmware and network configurations that facilitate rapid infection. Furthermore, this research evaluates several mitigation strategies, including implementing customized Intrusion Detection System (IDS) rules, network micro-segmentation, and automated patch management. The results demonstrate that a multi-layered defense approach can reduce the probability of successful infiltration by up to [insert percentage, e.g., 85%]. This study provides actionable insights for network administrators and IoT manufacturers to enhance the resilience of IoT ecosystems against evolving P2P-based threats.
KeywordsIoT Security, Mozi Botnet, Vulnerbility Asessment, P2P Malware, Cyber Mitigation, Network Forensic
|
DOIhttps://doi.org/10.29099/ijair.v10i1.1685 |
Article metrics10.29099/ijair.v10i1.1685 Abstract views : 86 | PDF views : 15 |
Cite |
Full Text Download
|
References
Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., ... & Savage, S. (2023). The end of the canonical IoT botnet: A measurement study of Mirai's descendants. arXiv. https://arxiv.org/abs/2309.01130
Atzori, L., Iera, A., & Morabito, G. (2022). A survey on IoT security: Application areas, security threats, and solution architectures. Computer Networks, 123(5), 234-250.
Conti, M., Dehghantanha, A., Franke, K., & Watson, S. (2023). IoT security: Review, blockchain solutions, and open challenges. Future Generation Computer Systems, 108, 583-606.
Fernández-Caramés, T. M., & Fraga-Lamas, P. (2022). A comprehensive survey on IoT security: Threats, vulnerabilities, and countermeasures. Journal of Network and Computer Applications, 182, 103048.
Kumar, R., Goyal, P., & Sharma, T. (2023). IoT security vulnerabilities and countermeasures: A survey. Security and Privacy, 5(2), e134.
Antonopoulos, A., & Ververis, V. (2023). A survey of IoT malware and detection methods based on communication features. IEEE Access, 11, 40210-40230.
Kolias, C., Kambourakis, G., Stavrou, A., & Gritzalis, D. (2022). IoT botnet detection approaches: Analysis and recommendations. Future Internet, 14(3), 76.
Ferrag, M. A., Maglaras, L., Derhab, A., Mukherjee, M., & Janicke, H. (2023). Security and privacy issues in IoT devices and sensor networks. Journal of Information Security and Applications, 58, 102748.
Das, A., Kant, C., & Dutta, T. (2022). A survey on botnet architectures, detection, and defenses. Computer Security, 107, 105789.
Zhang, Y., Liu, Y., & Wang, L. (2023). IoT security: Vulnerabilities, attacks, and countermeasures. ACM Computing Surveys, 55(6), 123-145.
Pratama, D., & Santoso, A. (2022). Keamanan aplikasi Internet of Things (IoT) sistem smart home. Jurnal Informatika, 14(2), 45-60.
Siregar, A., & Nugroho, R. (2023). Pengenalan pola serangan pada Internet of Things (IoT) menggunakan machine learning. Jurnal Teknologi Informasi, 17(3), 78-92.
Rahmadani, Y., & Fauzan, T. (2022). Review on security threat and solution of Internet of Things technology. Jurnal Teknik Elektro dan Informatika, 15(1), 25-38.
Wibowo, R., & Hidayat, A. (2023). Tinjauan ancaman dan risiko pada sistem keamanan Internet of Things. Jurnal Keamanan Siber, 6(2), 33-49.
Syahputra, M., & Rachmat, H. (2023). Deteksi botnet IoT menggunakan autoencoder dan decision tree. Jurnal Sistem Komputer, 10(1), 55-71.
Susanto, F., & Kurniawan, D. (2022). Analisis keamanan komputer di era Internet of Things: Studi kasus Mirai malware. Jurnal Ilmu Komputer, 8(4), 102-115.
Lestari, N., & Wijaya, P. (2023). Deteksi serangan botnet pada jaringan Internet of Things menggunakan metode machine learning. Jurnal Teknik Informatika, 21(2), 67-83.
Guo, Q., & Yu, S. (2024). Mozi botnet analysis: Understanding the P2P-based DHT structure and its propagation mechanism. Journal of Computer Virology and Hacking Techniques, 20(1), 45-58.
[19] Latif, S., et al. (2023). IoT forensics: Tracing the Mozi botnet activities in smart home environments. IEEE Internet of Things Journal, 10(4), 3120-3135.
Zhou, W., & Jia, Y. (2023). A lightweight filtering mechanism for P2P-based IoT botnet mitigation. Computers & Security, 128, 103145.
Wang, H., & Sun, J. (2023). Behavioral analysis of DHT-based botnets: The case of Mozi. Future Generation Computer Systems, 139, 210-225.
Nguyen, T. G., et al. (2023). Machine learning-based detection of P2P botnets in resource-constrained IoT devices. Information Sciences, 622, 540-558.
Hussain, F., et al. (2023). A survey of AI-based detection of Mozi and its variants in IoT networks. Ad Hoc Networks, 141, 103079.
Al-Rawi, O., et al. (2024). The evolution of IoT malware: From Mirai to Mozi and beyond. IEEE Communications Surveys & Tutorials, 26(1), 112-145.
Bojadzhiu, S., et al. (2023). Characterizing the P2P communication of Mozi botnet via honeypot data analysis. Journal of Network and Systems Management, 31(2), 34.
Li, Z., et al. (2023). Identifying Mozi botnet nodes using graph neural networks and traffic features. Knowledge-Based Systems, 260, 110156.
Silva, L., & Santos, N. (2023). Strengthening IoT gateways against P2P-based malware infiltration. Journal of Systems Architecture, 135, 102812.
Chen, Y., et al. (2022). Measuring the Mozi botnet: A global perspective on P2P botnet lifecycle. Proceedings of the ACM on Measurement and Analysis of Computing Systems, 6(2), 1-26.
Sethi, K., et al. (2023). Explainable AI for IoT botnet detection: Deep dive into Mozi and Mirai features. IEEE Transactions on Information Forensics and Security, 18, 1567-1582.
Ullah, I., & Mahmoud, Q. H. (2022). A scheme for detecting Mozi botnet in IoT using ensemble machine learning. International Journal of Critical Infrastructure Protection, 38, 100539.
Zhang, J., et al. (2023). Adversarial attacks and defenses in P2P-based IoT botnet detection. Network Security, 114, 102450.
Prasad, S., & Rohokale, V. (2023). Security orchestration for IoT networks: Mitigating P2P botnet propagation. Wireless Personal Communications, 130(2), 1245-1262.
Firdous, S. N., et al. (2023). Modeling the spread of Mozi botnet in heterogeneous IoT networks. Complexity, 2023, 5589012.
Abdel-Basset, M., et al. (2023). A hybrid deep learning model for detecting Mozi botnet in industrial IoT. IEEE Transactions on Industrial Informatics, 19(5), 6789-6801.
Zhu, Y., et al. (2024). Robustness of P2P botnets: Analyzing the DHT structure of Mozi against node churn. Journal of Information Security, 15(1), 88-102.
Putra, A., & Sari, I. (2023). Analisis kelemahan protokol telnet pada perangkat IoT terhadap serangan brute-force Mozi. Jurnal Teknoinfo, 17(1), 12-25.
Hidayatullah, M., & Utama, S. (2023). Mitigasi serangan botnet pada jaringan sensor nirkabel menggunakan metode rate-limiting. Jurnal Nasional Teknik Elektro dan Teknologi Informasi (JNTETI), 12(3), 201-215.

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
________________________________________________________
The International Journal of Artificial Intelligence Research
Organized by: Prodi Teknik Informatika Fakultas Teknologi Bisnis dan Sains
Published by: Universitas Dharma Wacana
Jl. Kenanga No. 03 Mulyojati 16C Metro Barat Kota Metro Lampung
Email: jurnal.ijair@gmail.com

This work is licensed under Creative Commons Attribution-ShareAlike 4.0 International License.













Download