Jul 2026· International Conference on Information and Communicatiaon Technology· pp. 1-6· 0 citations· 20 references
Abstract
Internet of Things (IoT) device security remains a concern due to their limited computational resources and increasing exposure to network-based cyberattacks. While recent IoT security research has focused on machine-learning and blockchain-based defense mechanisms, many of these approaches introduce computational overhead that may not be suitable for resource-constrained devices. This study investigates lightweight host-based countermeasures against network-level spoofing and phishing attacks targeting IoT environments. Specifically, the research examines attack entry points, classifies associated vulnerabilities, and evaluates three practical defense mechanisms: packet analysis using Wireshark, port monitoring using iptables, and host file reconfiguration. Detection is performed through the identification of abnormal TCP communication patterns, unauthorized port activity, and malicious-domain access attempts. A controlled experimental environment based on a Raspberry Pi IoT platform was used to assess the effectiveness and resource consumption of each approach. The results indicate that host file reconfiguration achieved the highest detection accuracy (96%) with the lowest CPU overhead (7%), while the combined deployment of all mechanisms achieved a 99% blocking success rate. The findings demonstrate that lightweight host-based defenses can provide protection against phishing and spoofing attacks while maintaining operational suitability for resource-constrained IoT devices.
Traditional Internet of Things (IoT) security solutions often rely on heavy cloud-based or gateway-class infrastructure, which is frequently unsuitable for resource-limited hardware due to latency, power, and memory constraints. This paper proposed a resource-aware behavioral Intrusion Detection System (IDS) designed for highly constrained IoT devices. To address these challenges, the proposed system implements real-time application-layer monitoring on an ESP32 Microcontroller Unit (MCU) and utilizes an offline-trained logistic regression model for autonomous, on-device inference. The detection mechanism extracts behavioral features, such as request rates, failed authentication attempts, and invalid resource access within sliding time windows to estimate attack probabilities. Experimental evaluations under controlled scenarios involving flood, brute force, and scan attacks demonstrate that the system achieves high accuracy, precision, and recall. These findings indicate that effective cyber intrusion detection and local mitigation can be successfully executed directly on a single MCU while preserving stable runtime performance and minimal memory usage. Finally, this paper highlights the need for further optimizations to improve robustness and scalability.
Sofyan Bisher, Anas Fawaza, Tarek Mawed et al.· International Conference on...· 0 citations
The rapid growth of Internet of Things (IoT) devices in smart homes, industries, and urban infrastructure has increased the global cyber-attack surface. Many IoT devices use lightweight communication protocols and often lack strong authentication, making them easy targets for automated cyberattacks. This paper introduces ShadowNet, a virtual IoT honeypot framework designed to capture and study malicious interactions in IoT environments. The system simulates various IoT communication services, including HTTP, SSH, and MQTT, letting attackers interact with it as if it were a real vulnerable IoT device. The framework records attacker behavior, such as login attempts, command execution, payload injections, and request metadata. To improve attack identification, the system uses a Random Forest-based machine learning model to classify network traffic as normal or malicious based on activity patterns. A web-based monitoring dashboard also visualizes attack statistics and intrusion activity by protocol. In experimental deployments, the framework captured multiple attack patterns, including SSH brute-force attempts, HTTP credential stuffing, and malicious MQTT payload injections. This shows the effectiveness of honeypot-based monitoring paired with machine learning techniques, achieving high accuracy in detecting malicious IoT traffic. The proposed system offers a scalable and cost-effective solution for real-time IoT security monitoring.
Mahesh S. Shinde, Vijendra Sarode, Harsh Sarulkar et al.· 2026 4th International Confe...· 0 citations
This paper analyzes eight major IT/OT threats in the view of their empowerment via steganography to anticipate the evolution of malicious software targeting IT/OT scenarios when endowed with advanced data hiding schemes, i.e., multi level steganography.
Przemysław Szary, Wojciech Mazurczyk, L. Caviglione· ACM Computing Surveys· 0 citations
These findings demonstrate that Edge-ZTA provides an efficient, privacy-preserving, and scalable cybersecurity framework capable of mitigating sophisticated multi-stage cyberattacks while satisfying the stringent performance requirements of next-generation Industrial IoT infrastructures.
Ahmed Ramzi Rashid, Zaydon L. Ali, Ahmed Sedeeq Baker Al-Doori· Al-Noor Journal of Engineeri...· 0 citations
The rapid growth of the Internet of Things (IoT) has enabled seamless communication among billions of interconnected devices. However, the heterogeneous and resource-constrained nature of IoT networks makes them vulnerable to cyberattacks such as unauthorized access, spoofing, malware injection, and denial-of-service attacks. This research proposes an Object Identifier Detection System (OIDS) to strengthen IoT network security by uniquely identifying and authenticating connected devices based on object identifiers and behavioral characteristics. This paper presents a novel Object Identifier Detection System (OIDS) to enhance security in Internet of Things (IoT) networks. The proposed framework authenticates IoT devices using unique object identifiers and continuously monitors network traffic to detect unauthorized devices and malicious activities. It integrates machine learning-based anomaly detection with object identifier verification to improve attack detection accuracy while reducing false positives. Experimental evaluation demonstrates that the proposed system provides secure, scalable, and efficient protection for IoT environments compared with conventional intrusion detection approaches.
Tarun Badiwal, S. Meena, S. Jayswal et al.· International Journal of Inn...· 0 citations
This paper presents a rigorous and experimentally grounded analysis of security mechanisms for embedded Internet of Things (IoT) systems, ensuring that all reported findings are directly verified from primary published sources. The study systematically examines six key domains: hardware-rooted secure boot and remote attestation on application-processor-class IoT devices; benchmarking of post-quantum cryptographic algorithms on constrained platforms, highlighting the efficiency of CRYSTALS-Kyber on mid-range hardware and the performance challenges on ultra-constrained devices; evaluation of the NTRU cryptographic scheme on edge IoT nodes; experimental analysis of the Bluetooth Key Negotiation of Bluetooth (KNOB) attack across multiple chipsets and devices; assessment of firmware vulnerability taxonomies along with analysis tools for consumer IoT firmware; and characterization of IoT attack traffic, with a focus on the predominance of network-layer attacks targeting Telnet interfaces. For each domain, the paper details the experimental setup, methodology, validated results, and associated limitations. It also critically addresses inconsistencies in prior literature by identifying and correcting instances where unsupported numerical claims were previously reported. A comprehensive comparative analysis is provided to consolidate all verified findings, offering a reliable and source-consistent perspective on IoT security research.
M. More, S. N, J. R. Nandwalkar et al.· 2026 International Conferenc...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.