Smart Home Bot Detection Using Network Analysis

Smart Home Bot Detection Using Network Analysis

Abstract— We have seen an ever-increasing amount of malicious attacks like the Mirari botnet, to spyware, and ransomware. A lot of the times a botnet is at the heart of some of these attacks, more specifically a DDoS or similar type of attack. Due to the uptick of smart home devices and the weak security some of these devices have the chances are that these could be prone to be compromised relatively easy.
I. BACKGROUND
In this paper we will analyze the basic principles of these botnets and how smart home devices could be used to implement a large scale attack. We will also discuss what examples we have at our disposals of how botnets in general are detected by analyzing network traffic and how we could use this to fit smart home devices. We will also go over the security limitations these devices inherently have. We will discuss the manufacture’s role in this process, should they implement security measure out of the box or should the user be solely responsible or a mix in-between. We will also setup a lab and utilizing a smart home device and packet capture technology see how it could be compromised and how we could have prevented it. We will have the network packets that are captured analyzed to see what patterns emerge for an infected system and what could be done when a compromised device is found. We will also discuss what could be added to enhance the security of the smart home devices and their networks, as it would seem that these are going to become more common place overtime.

Figure 1
As we can see in Figure 1 [1], the amount of attaks is increasing yearly. We can also see that the amount of smart home devices has exploded recently as well (Figure 2) [2].

Figure 2
Lastly, we will discuss where the future is headed for smart home devices in the via of becoming compromised and if our analysis could help in determine the best next steps to ensure that that devices are as secure as possible without compromising the useability.

II. RELATED WORK

There has been interesting work done in the field of network analysis and botnet detection. Out intent is to look at how these tasks were accomplished and apply towards the goal of this project.
One way botnet detection has been performed is by looking at SYN flooding. The basic premise here is that a compromised machine will continuously send SYN packets to the targeted system. The targeted system then hands to process this SYN packet in a normal way. When this is used as part of a botnet a huge amount of SYN packets can be flooded to the target system and spend all system resources attempting to process these SYN packets. In the paper “Analysis of the SYN Flood DoS Attack” the writers analyze traffic when a SYN attack is being reproducded and when there is no ongoing attack. There is clear indication from a network analysis standpoint when a SYN flood attack is ongoing. [6]
While we are wanting a solution for home smart home devices it is also good to look at work in the DDoS detection field as whole to get a deeper understanding. Considering that another method of detecting SYN attacks is detailed under the paper “A covariance analysis model for DDoS attack detection”. In this paper they detailed a rather sophisticated and accurate covariance detection method. [4]
There has also been progress at analyzing different packet characteristics in the core and edge networks. This method is interesting because a detailed analysis of packet characteristics can help in detection a more stealth attack. [5]

II. PROPOSED METHODOLOGY
The solution is complicated. More and more smart home devices are being sold and consumers mostly either do not care or do not know about the inherit security risks. Where to many consumers the potential benefits outweigh the potential privacy and security concerns. [3]
We know that the intrinsic nature of many smart home devices, weather it is a smart plug or smart thermostat they are potentially running on a schedule in an attempt to make you home more energy efficient or the very act of collecting data to do this are both forms of privacy and security risks. For the purpose of this project we are going to discuss hardware and software security vulnerabilities that could enable the smart home device to be become part of a botnet and how we can use network traffic analysis to detect and learn from these compromised smart home devices.

Network Traffic and Botnet
In the ISP world when a DDoS attack is detected the usually method is a detected bandwidth anomaly where the victim IP is being bombarded with some type of traffic from the attacker or attackers usually. This traffic can spike very quickly making it easy to determine that an attack is ongoing. Also, typically while there are usually many attackers there is usually just one or few victims. So while the net affect of bandwidth created by a botnet can be great if we turn this idea around and attempt to detect the anomaly from a single infected member of the botnet then it becomes much more difficult. And in the cases of ISP this can be like trying to find a needle in a haystack.
Proposal: Attacker to Victim Detection
This project is proposing a method of detection that would happen at the compromised attacker side. Not to be confused with the perpetrator of this attack but rather detect if smart home devices have become unknowingly compromised and a part of the attack in a bot net scenario. This would not eliminate the need for victim detection on the ISP side but would greatly assist in overall reduction of botnet type of attacks coming from smart home devices. First, we need to understand how a botnet communicates with the outside world because that is the part of the network traffic, we will be analyzing. Weather it is communicating with a command and control server or sending SYN floods directly to a victim, having a clear picture of how botnets communicate will help in fully understanding and detecting a compromised smart home device. [4][6]

Analyzing Typical Traffic
To become familiar with how a smart home device typically works we would need to gather a baseline of traffic and analyses it to see what how it communicates normally. To do this we will setup a sandbox environment with the following devices:
• Lenovo laptop
o OS: Kali Linux
o Software: Netcat, Wireshark, INetSim
• Linksys router
• Smart Home Device: PowerBear Smart Plug

Figure 3 – Network Diagram

We will connect all devices to the Linksys router and setup basic configuration on the smart plug. Next we will monitor packets from and to the smart home device. Specifically, we will want to analyze traffic when its idle, when its switched on and off, and when scheduling changes the on/off settings.

Penetration Testing for Vulnerabilities
One of the main exploration of this project is to determine how vulnerable a typical smart home devices is out of the box and how susceptible it will be with minimal configuration. For this part of the project we will subject the smart plug to various penetration testing from the Kali OS. Using this information, we will install a form of a bot using the vulnerabilities we found.
After that we will need to gather more network traffic for analysis and compare it to the typical network traffic. Using network analysis we should be able to see the differences in when the device was running normally and when it became compromised.

REFERENCES
[1] M. from T. Emmons, T. Emmons, R. R. | Yesterday, Natasha Lane | 3 days ago, Chen Gour-Arie | 4 days ago, Richi Jennings | 3 days ago, R. J. | M. 16, and George V. Hulme | Mar 15, “Large, Complex DDoS Attacks on the Rise in 2020,” Security Boulevard, 28-Jul-2020. [Online]. Available: https://securityboulevard.com/2020/07/large-complex-ddos-attacks-on-the-rise-in-2020/. [Accessed: 23-Mar-2021].
[2] “Report: 20% of U.S. broadband households to get smart home devices by next year,” test drive, 24-Oct-2014. [Online]. Available: https://pmloeffler.wordpress.com/2014/10/24/report-20-of-u-s-broadband-households-to-get-smart-home-devices-by-next-year/. [Accessed: 23-Mar-2021].
Available: http://stevemorse.org/phonetics/bmpm2.htm
[3] Stanislav Mamonov, Marios Koufaris. (2020) Fulfillment of higher-order psychological needs through technology: The case of smart thermostats. International Journal of Information Management 52, pages 102091.
[4] Shuyuan Jin and D. S. Yeung, “A covariance analysis model for DDoS attack detection,” 2004 IEEE International Conference on Communications (IEEE Cat. No.04CH37577), Paris, France, 2004, pp. 1882-1886 Vol.4, doi: 10.1109/ICC.2004.1312847.
[5] L. Feinstein, D. Schnackenberg, R. Balupari and D. Kindred, “Statistical approaches to DDoS attack detection and response,” Proceedings DARPA Information Survivability Conference and Exposition, Washington, DC, USA, 2003, pp. 303-314 vol.1, doi: 10.1109/DISCEX.2003.1194894.
[6] M. Bogdanoski, T. Shuminoski, and A. Risteski, “Analysis of the SYN Flood DoS Attack,” International Journal of Computer Network and Information Security, vol. 5, no. 8, pp. 15–11, 2013..