IoT Botnet & Ransomware Classification
Classifying IoT botnet traffic and ransomware families with graph neural networks, Kolmogorov-Arnold networks, and lightweight hashing.
Traffic classification dashboard showing malware family clusters
Overview
This project line turns raw network traffic and binaries into actionable threat intelligence. We classify IoT botnet traffic using graph neural networks and Kolmogorov-Arnold Networks — an emerging alternative to standard MLP architectures — and study lightweight hashing techniques for grouping ransomware samples into families without full static or dynamic analysis.
Related publications
- Classifying IoT Botnet Attacks with Kolmogorov-Arnold Networks: A Comparative Analysis of Architectural Variations — IEEE Access, 2025
- Investigating the Effectiveness of Different GNN Models for IoT-Healthcare Systems Botnet Traffic Classification — Secure Health, book chapter, 2025
- Classification of Ransomware Families Based on Hashing Techniques — Conference on Information Technology and its Applications (CITA), 2023
Status
Completed. Running from 2023 to 2025, this project line delivered three publications — spanning hashing-based ransomware classification, Kolmogorov-Arnold Network-based IoT botnet detection, and an extension of botnet traffic classification into the IoT-healthcare setting.