[Paper Review] Turning Internet of Things(IoT) into Internet of Vulnerabilities (IoV) : IoT Botnets
The paper analyzes IoT botnets as a major security risk, detailing their anatomy, attack methods, notable incidents, and mitigation strategies including cyber insurance considerations.
Internet of Things (IoT) is the next big evolutionary step in the world of internet. The main intention behind the IoT is to enable safer living and risk mitigation on different levels of life. With the advent of IoT botnets, the view towards IoT devices has changed from enabler of enhanced living into Internet of vulnerabilities for cyber criminals. IoT botnets has exposed two different glaring issues, 1) A large number of IoT devices are accessible over public Internet. 2) Security (if considered at all) is often an afterthought in the architecture of many wide spread IoT devices. In this article, we briefly outline the anatomy of the IoT botnets and their basic mode of operations. Some of the major DDoS incidents using IoT botnets in recent times along with the corresponding exploited vulnerabilities will be discussed. We also provide remedies and recommendations to mitigate IoT related cyber risks and briefly illustrate the importance of cyber insurance in the modern connected world.
Motivation & Objective
- Highlight the security vulnerabilities inherent in widely deployed IoT devices.
- Explain how IoT botnets operate within the TCP/IP framework and access networks.
- Survey major IoT-enabled DDoS incidents and the malware families behind them.
- Discuss mitigation strategies and the evolving role of cyber insurance in cyber risk management.
Proposed method
- Describe the IoT landscape and its security shortcomings in the context of access networks and DSL-based architectures.
- Explain TCP/IP protocol layers and IoT-specific traffic patterns relevant to botnets.
- Review and categorize notable IoT botnet malware families and their evolution.
- Present case studies of prominent DDoS incidents attributed to IoT botnets (e.g., Mirai, BASHLITE) and their impact.
- Discuss mitigation approaches, DDoS-as-a-Service dynamics, and the relevance of cyber insurance.
Experimental results
Research questions
- RQ1What makes IoT devices particularly vulnerable to botnet-based DDoS attacks?
- RQ2How do IoT botnets operate within the internet infrastructure to launch large-scale attacks?
- RQ3What are the major IoT malware families and how have they evolved over time?
- RQ4What incident patterns illustrate the scale and impact of IoT-driven DDoS attacks, and how can they be mitigated?
Key findings
- IoT devices provide a large, globally distributed pool of vulnerable endpoints used to generate massive DDoS traffic (e.g., up to 1.2 Tbps in cited attacks).
- Mirai and BASHLITE are key drivers of IoT botnets with widespread infection and high traffic floods across GRE, SYN, UDP, HTTP, and other vectors.
- DDoS incidents attributed to IoT botnets have demonstrated unprecedented scale, including attacks surpassing 600 Gbps and 1 Tbps.
- There is a growing ecosystem for DDoS-as-a-Service, enabling inexpensive, scalable attacks via compromised IoT devices.
- Malware evolution shows a progression from simple brute-force campaigns to sophisticated, architecturally adaptable botnets with cross-architecture capabilities.
- Mitigation strategies involve multi-layered defense, traffic scrubbing, and consideration of cyber insurance in risk management.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.