Intelligent Detection Method for In-the-Wild Exploit Attacks in Distributed IoT Networks
DOI:
https://doi.org/10.4108/eetsis.12657Keywords:
IoT, Distributed Networks and Systems, In-the-Wild Exploitation, Threat Detection, OSINTAbstract
INTRODUCTION: In distributed IoT networks, massive devices, edge nodes and cloud platforms exchange data via open protocols, making device exploit attacks a severe threat to business continuity, data security and cross-domain propagation. Existing rule-based methods fail to balance real-time performance, accuracy and attack localization against rapidly mutating, obfuscated and large-scale in-the-wild exploits.
OBJECTIVES: To address the above limitations, this paper aims to propose an intelligent detection method integrating hybrid deep learning and open-source intelligence correlation for distributed IoT systems.
METHODS: First, HTTP packet preprocessing extracts suspected attack samples to mitigate extreme class imbalance. Second, a BERT-CNN coupled model classifies suspicious packets automatically. Finally, attack vector regression correlation with public vulnerabilities, PoCs and threat intelligence realizes accurate 1Day/NDay attack identification.
RESULTS: Experiments show the method achieves over 99.99% accuracy and 99.98% F1-score on real datasets. The IoT_Exploits_Founder system discovered 13 new in-the-wild exploits within one month in real environment. This study also supplements quantitative comparisons with representative methods, online deployment measurements of latency, memory overhead and throughput, and ablation studies for the attack-vector regression threshold and feature weights.
CONCLUSION: The proposed method provides effective support for AI-driven security monitoring in distributed IoT systems, with strong real-time edge applicability and robustness.
References
[1] Neshenko N, Bou-Harb E, Crichigno J, Kaddoum G, Ghani N. Demystifying IoT security: An exhaustive survey on IoT vulnerabilities and a first empirical look on Internet-scale IoT exploitations. IEEE Commun. Surv. Tutorials. 2019;21(3):2702-33.
[2] Sabottke C, Suciu O, Dumitraș T. Vulnerability disclosure in the age of social media: Exploiting twitter for predicting Real‑World exploits. In: Proceedings of the 24th USENIX Security Symposium; 2015 Aug 12‑14; Washington, DC, USA. Berkeley: USENIX Association; 2015. p. 1041‑1056.
[3] Bilge L, Dumitraş T. Before we knew it: an empirical study of zero-day attacks in the real world. In: Proceedings of the 2012 ACM conference on Computer and communications security; 2012 Oct 16-18; Raleigh, NC, USA. New York: ACM; 2012. p. 833-844.
[4] Elder S, Rahman MR, Fringer G, Kapoor K, Williams L. A survey on software vulnerability exploitability assessment. ACM Comput. Surv. 2024;56(8):1-41.
[5] Roesch M. Snort: Lightweight intrusion detection for networks. In: Proceedings of the 13th USENIX Conference on System Administration (LISA); 1999 Nov 7-12; Seattle, WA, USA. Berkeley: USENIX Association; 1999. p. 229-238.
[6] Sommestad T, Holm H, Steinvall D. Variables influencing the effectiveness of signature-based network intrusion detection systems. Inf. Secur. J. 2022;31(6):711-728.
[7] Tavallaee M, Bagheri E, Lu W, Ghorbani AA. A detailed analysis of the KDD CUP 99 data set. In: Proceedings of the 2009 IEEE symposium on computational intelligence for security and defense applications; 2009 Jul 8-10; Ottawa, Canada. IEEE; 2009. p. 1-6.
[8] Shiravi A, Shiravi H, Tavallaee M, Ghorbani AA. Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Comput. Secur. 2012;31(3):357-374.
[9] Ring M, Wunderlich S, Grüdl D, Landes D, Hotho A. Flow-based benchmark data sets for intrusion detection. In: Proceedings of the 16th European Conference on Cyber Warfare and Security (ECCWS); 2017 Jun 29; South Oxfordshire, UK. South Oxfordshire, UK: ACPI; 2017. p. 361-369.
[10] Lee W, Stolfo S. Data mining approaches for intrusion detection. In: Proceedings of the 7th USENIX Security Symposium; 1998 Jan 26‑29; San Antonio, TX, USA. Berkeley: USENIX Association; 1998. p. 79‑94.
[11] Khan L, Awad M, Thuraisingham B. A new intrusion detection system using support vector machines and hierarchical clustering. VLDB J. 2007;16(4):507-521.
[12] Nguyen TT, Armitage G. A survey of techniques for internet traffic classification using machine learning. IEEE Commun. Surv. Tutorials. 2008;10(4):56-76.
[13] Sommer R, Paxson V. Outside the closed world: On using machine learning for network intrusion detection. In: Proceedings of the 2010 IEEE symposium on security and privacy; 2010 May 16-19; Oakland, CA, USA. IEEE Computer Society; 2010. p. 305-316.
[14] Ring M, Wunderlich S, Scheuring D, Landes D, Hotho A. A survey of network-based intrusion detection data sets. Comput. Secur. 2019;86:147-167.
[15] Ma J, Saul LK, Savage S, Voelker GM. Identifying suspicious URLs: an application of large-scale online learning. In: Proceedings of the 26th annual international conference on machine learning; 2009 Jun 14-18; Montreal, Canada. ACM; 2009. p. 681-688.
[16] Ma J, Saul LK, Savage S, Voelker GM. Beyond blacklists: learning to detect malicious web sites from suspicious URLs. In: Proceedings of the 15th ACM SIGKDD international conference on Knowledge discovery and data mining; 2009 Jun 28-Jul 1; Paris, France. New York: ACM; 2009. p. 1245-1254.
[17] Zhao P, Hoi SC. Cost-sensitive online active learning with application to malicious URL detection. In: Proceedings of the 19th ACM SIGKDD international conference on Knowledge discovery and data mining; 2013 Aug 11-14; Chicago, IL, USA. New York: ACM; 2013. p. 919-927.
[18] Yun X, Xie J, Li S, Zhang Y, Sun P. Detecting unknown HTTP-based malicious communication behavior via generated adversarial flows and hierarchical traffic features. Comput. Secur. 2022;121:102834.
[19] Hodo E, Bellekens X, Hamilton A, Dubouilh PL, Iorkyase E, Tachtatzis C, Atkinson R. Threat analysis of IoT networks using artificial neural network intrusion detection system. In: Proceedings of the 2016 International symposium on networks, computers and communications (ISNCC); 2016 May 11-13; Yasmine Hammamet, Tunisia. IEEE; 2016. p. 1-6.
[20] Thamilarasu G, Chawla S. Towards deep-learning-driven intrusion detection for the internet of things. Sensors. 2019;19(9):1977.
[21] Muna AH, Moustafa N, Sitnikova E. Identification of malicious activities in industrial internet of things based on deep learning models. J. Inf. Secur. Appl. 2018;41:1-11.
[22] Abdel-Basset M, Hawash H, Chakrabortty RK, Ryan MJ. Semi-supervised spatiotemporal deep learning for intrusions detection in IoT networks. IEEE Internet Things J. 2021;8(15):12251-12265.
[23] Tsimenidis S, Lagkas T, Rantos K. Deep learning in IoT intrusion detection. J. Netw. Syst. Manag. 2022;30(1):8.
[24] Suciu O, Nelson C, Lyu Z, Bao T, Dumitraș T. Expected exploitability: Predicting the development of functional vulnerability exploits. In: Proceedings of the 31st USENIX Security Symposium (USENIX Security 22); 2022 Aug 10-12; Boston, MA, USA. Berkeley: USENIX Association; 2022. p. 377-394.
[25] Adewopo V, Gonen B, Adewopo F. Exploring open source information for cyber threat intelligence. In: Proceedings of the 2020 IEEE International Conference on Big Data (Big Data); 2020 Dec 10-13; Atlanta, GA, USA. IEEE; 2020. p. 2232-2241.
[26] Minaee S, Kalchbrenner N, Cambria E, Nikzad N, Chenaghlu M, Gao J. Deep learning-based text classification: a comprehensive review. ACM Comput. Surv. 2021;54(3):1-40.
[27] Kim Y. Convolutional neural networks for sentence classification. In: Proceedings of the 2014 conference on empirical methods in natural language processing (EMNLP); 2014 Oct 25-29; Doha, Qatar. Doha: Association for Computational Linguistics; 2014. p. 1746-1751.
[28] Vaswani A, Shazeer N, Parmar N, Uszkoreit J, Jones L, Gomez AN, Kaiser Ł, Polosukhin I. Attention is all you need. Adv. Neural Inf. Process. Syst. 2017;30.
[29] Devlin J, Chang MW, Lee K, Toutanova K. Bert: Pre-training of deep bidirectional transformers for language understanding. In: Burstein J, Doran C, Solorio T, editors. Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers); 2019 Jun 2-7; Minneapolis, MN, USA. Minneapolis: Association for Computational Linguistics; 2019. p. 4171-4186.
[30] Saeed S, Suayyid SA, Al-Ghamdi MS, Al-Muhaisen H, Almuhaideb AM. A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience. Sensors. 2023;23(16):7273.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Xiaohu Wu, Mingyuan Zhang, Xiaolei Liu, Xiaojian Zhang, Ke Jing

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.