Skip to content
All projects
IoT SecurityCompleted

IoT Botnet & Ransomware Classification

Classifying IoT botnet traffic and ransomware families with graph neural networks, Kolmogorov-Arnold networks, and lightweight hashing.

Traffic classification dashboard showing malware family clusters

Overview

This project line turns raw network traffic and binaries into actionable threat intelligence. We classify IoT botnet traffic using graph neural networks and Kolmogorov-Arnold Networks — an emerging alternative to standard MLP architectures — and study lightweight hashing techniques for grouping ransomware samples into families without full static or dynamic analysis.

  • Classifying IoT Botnet Attacks with Kolmogorov-Arnold Networks: A Comparative Analysis of Architectural Variations — IEEE Access, 2025
  • Investigating the Effectiveness of Different GNN Models for IoT-Healthcare Systems Botnet Traffic Classification — Secure Health, book chapter, 2025
  • Classification of Ransomware Families Based on Hashing Techniques — Conference on Information Technology and its Applications (CITA), 2023

Status

Completed. Running from 2023 to 2025, this project line delivered three publications — spanning hashing-based ransomware classification, Kolmogorov-Arnold Network-based IoT botnet detection, and an extension of botnet traffic classification into the IoT-healthcare setting.

Interested in this line of research?

Get in touch to discuss collaboration, data access, or joining the project as a student researcher.