Linux IoT Malware Variant Classification Using Binary Lifting and Opcode Entropy

11Citations
Citations of this article
11Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Binary function analysis is fundamental in understanding the behavior and genealogy of malware. The detection, classification, and analysis of Linux IoT malware and its variants present significant challenges due to the wide range of architectures supported by the Linux IoT platform. This study concentrates on static analysis using binary lifting techniques to extract and analyze Intermediate Representation (IR) opcode sequences. We introduce a set of statistical entropy-based features derived from these IR opcode sequences, establishing a practical and straightforward methodology for machine learning classification models. By exclusively analyzing function metadata and opcode entropy, our architecture-agnostic approach not only efficiently detects malware but also classifies its variants with a high degree of accuracy, achieving an F1 score of 97%. The proposed approach offers a robust alternative for enhancing malware detection and variant identification frameworks for IoT devices.

Cite

CITATION STYLE

APA

Ramamoorthy, J., Gupta, K., Shashidhar, N. K., & Varol, C. (2024). Linux IoT Malware Variant Classification Using Binary Lifting and Opcode Entropy. Electronics (Switzerland), 13(12). https://doi.org/10.3390/electronics13122381

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free