inklap

HIoT: heterogeneous information network based compromised IoT device detection

Meng Luo, Jianrong Zhang, Kai Zhou, Xinyan Wang, Cheng Yu, Baojiang Cui · Cybersecurity · 2026

Abstract Internet of things (IoT) devices are widely exploited by botnets and other cyberattacks to carry out various malicious activities. Traditional detection methods focus on specific device types or attack patterns and have limited coverage. In this paper, we propose a novel detection model for compromised IoT devices based on heterogeneous information networks (HINs), which can detect compromised IoT devices across different device types and attack scenarios. The model takes full advantage of the structural and semantic information in IoT SIM card logs, modeling IoT device communication as a HIN that includes different types of entities such as IoT devices, URLs, IPs, and domain names. We design meta-paths based on factors such as overlapping communication IPs, URL similarity, and reuse of network infrastructure to quantify the similarity between IoT devices. Using the similarity matrix of IoT devices and a small fraction of labeled data, we apply a label propagation algorithm to detect compromised IoT devices. We thoroughly evaluate and validate the model using a manually constructed dataset and raw data from a real-world network, demonstrating the effectiv

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً