Hatem A. Almazarqi

dblp:312/9302 · DBLP profile ↗
← Back
7ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0001-6644-493XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 5 first-author · 6 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 BotPro: Data-driven tracking & profiling of IoT botnets in the wild
abstract
The incorporation of the IoT into modern sociotechnical systems, alongside the rapid manufacturing of IoT devices with minimal embedded security, has significantly altered the cyber threat landscape. Consequently, modern cyberattacks now exploit compromised IoT devices to launch large-scale volumetric assaults or sophisticated advanced persistent threats (APTs) via carefully coordinated IoT botnets. Given the ever-changing structural dynamics of these botnets, tracking their activities presents significant challenges since malicious actors frequently adapt and employ new evasion techniques to expand their networks. This study introduces BotPro, a novel open-source tool built on a data-driven framework that captures and attributes the behavioural characteristics of IoT botnets. BotPro integrates honeypot telemetry, CTI feeds, and Internet topology data to profile scanning, infection, and propagation patterns, as well as cluster payloads to identify malware variants and assess AS-level risk exposure. Through a macroscopic measurement study spanning three years with 40 globally distributed honeypots covering 193 countries and 16K ASes, we show that BotPro can quantify the tolerance of Autonomous Systems (ASes) as a function of botnet scanning and propagation properties. Our clustering evaluation achieved a Silhouette score of 0.54 with low Davies–Bouldin index values, confirming the coherence and separation of identified botnet groups. Hence, our findings provide substantial context to security experts and network operators for effectively designing and implementing next-generation defence and mitigation measures against current and future IoT botnets.
Hatem A. Almazarqi, Mathew Woodyard, Angelos K. Marnerides
Comput. Secur.1
2025 Dynamics of Large-Scale DDoS Attacks Orchestrated by IoT Botnets
abstract
The increasing prevalence of Internet of Things (IoT) devices has created new vulnerabilities that malicious actors can exploit, particularly for orchestrating large-scale Distributed Denial of Service (DDoS) attacks via IoT botnets. These botnets take advantage of the inherent weaknesses in IoT devices to overwhelm network infrastructure, resulting in significant disruptions. In this work, we offer an Internet measurements study focusing on the AS-level distribution of DDoS traffic produced by IoT botnets and their attribution based on propagation patterns. Hence, with the use of graph-based metrics we correlate Cyber Threat Intelligence (CTI) data from globally distributed honeypots with real DDoS attacks to profile botnet propagation patterns and further identify key Internet Autonomous Systems (ASes) being tolerant to these attacks via an exemplar use case. Our results highlight device-level vulnerabilities acting as main vessels for IoT botnet propagation resulting to maximise their impact in terms of DDoS attack scale. In general, we argue that the herein reported work provides valuable insights from the real global Internet towards developing next-generation early identification and post-attack mitigation strategies of DDoS attacks instrumented by IoT botnets.
Hatem A. Almazarqi, Mathew Woodyard, Angelos K. Marnerides
ISCC1
2025 Stratification and Profiling of IoT Botnet Variants
abstract
IoT botnets have been adopted as the prime infrastructure for a plethora of cybercrime and modern cyberwarfare. Evidently, conventional defence approaches fail to capture the full spectrum of IoT botnet activity by virtue of attackers evading schemes and limited Internet visibility. In this work, we develop a novel macroscopic analysis framework that profiles malware strains through payload signatures gathered from malicious traffic, revealing distinct botnet variants and their infrastructure. Through payload clustering distilled by information retrieval properties and DNS-based infrastructure mapping, we systematically group botnet families, identifying distinct exploitation trends and infrastructure reuse patterns. Our longitudinal study over real pre-captured datasets for a $\mathbf{4}$-year period reveals widespread lack of blacklist coverage with $65.94 \%$ of discovered malicious IPs and $\mathbf{9 8. 9 7 \%}$ of associated domains not yet blacklisted. We pinpoint a growing trend of botnet operators leveraging cloud services such as AWS, OVH, and Linode, hosting their command-and-control (C2) servers on reputable domains to bypass security filters and extend operational longevity. Through demonstrating practical metrics to assess botnet scan volume, vulnerability trends, and infection rates, we stress the need to refine existing defence mechanisms. In parallel, we set solid ground for practical threat hunting and risk profiling for next-generation cybersecurity schemes.
Michael Photiades, Mathew Woodyard, Hatem A. Almazarqi, Angelos K. Marnerides
ISCC3
2024 Macroscopic Insights of IoT Botnet Dynamics Via AS-level Tolerance Assessment
abstract
The ubiquitous integration of the IoT in current sociotechnical systems alongside the manufacturing of IoT devices and IoT-enabled services equipped with minimal security, has profoundly altered the cyber-threat landscape. Consequently, the overwhelming majority of cyberattacks utilise compromised IoT devices as a vessel for initiating large scale volumetric (e.g., DDoS) or stealthy Advanced Persistent Threats (APTs) such as ransomware through well orchestrated IoT botnets. Due to the constantly evolving nature of these botnets and their diverse structural characteristics, tracking their activities poses considerable challenges since malicious actors and botnet owners often adopt new strategies to evade detection and expand their botnet network. Evidently, Autonomous Systems (ASes) and their implied organisational and regulatory properties play a crucial role in botnet propagation. In this paper, we present a novel and extensive macroscopic measurement study quantifying AS-level tolerance in the context of IoT botnet behavioral dynamics across the global IPv4 address space. In order to verify and justify our hypotheses in terms of AS-level tolerance we conduct a longitudinal analysis over 3.8M malicious events triggered by IoT botnets across over 8K ASes using measurements gathered through globally distributed honeypots, IP blacklists and Internet regional registries for a three year period. We argue that the findings in the herein work can greatly benefit a range of stakeholders designing, operating, and managing current defense mechanisms as well as contributing significantly towards the evolution of next generation cyber defense mechanisms.
Hatem A. Almazarqi, Mathew Woodyard, Angelos K. Marnerides
ICC1
2023 Tracking IoT P2P Botnet Loaders in the Wild
abstract
Evidently, centralised botnets are nowadays considered as easy targets for take-down efforts by law enforcement and computer security researchers. Hence, malicious actors transitioned towards the implementation of Peer-to-Peer (P2P) IoT botnets such to solidify their infrastructures, avoid single points of failure and further evade back tracking. Consequently, due to the highly distributed persona of modern P2P botnets, the detection of critical nodes to aid for the effective capturing of emerging threat vectors in such setups evolved into a challenging task. In this work, we conduct a novel 24-month longitudinal study based on real Internet measurements from globally distributed honeypots focusing on propagation trends of P2P IoT botnets. In order to achieve this, we develop graph-based centrality metrics to attribute AS-level connectivity characteristics to botnet and malware propagation as well as relating AS-level tolerance for botnet malware hosts we refer to as loaders. In general, we argue that the proposed methodology and outcomes of the herein study, can significantly benefit security experts and network operators towards the design of mitigation measures against present and future P2P botnets.
Hatem A. Almazarqi, Mathew Woodyard, Troy Mursch, Dimitrios P. Pezaros, Angelos K. Marnerides
ICC1
2022 Macroscopic Analysis of IoT Botnets
abstract
The adoption of the IoT by modern sociotechnical systems in synergy with the rapid deployment of insecure IoT devices and services has transformed the cyber-threat landscape. Thus, the vast majority of cyberattacks are underpinned by the orchestration of compromised IoT devices that are globally distributed and controlled through carefully designed IoT botnets. Contrary to conventional belief, cybersecurity vectors instrumented by such botnets are not always uniformly distributed across Internet Autonomous Systems (ASes). By virtue of network structural characteristics imposed by each individual Autonomous System (AS) as well as the diversity in terms of AS-level cybersecurity policies, the spatiotemporal manifestation of IoT botnets differs. In this work, we provide a novel measurement study that empirically quantifies AS tolerance of IoT botnet propagation in the global IPv4 Internet. We assess and correlate measurements gathered by globally distributed honeypots, Internet regional registries and IP blacklists for a 15-month period and observe more than 3.2M malicious events triggered by IoT botnets spanning 9.5K ASes. Our work demonstrates that ASes connected to a low number of providers are prone to embrace a high portion of malicious activities. Hence, we provide evidence on concentrated botnet activities and determine the effectiveness of widely used IP blacklists. In general, this study contributes towards empowering knowledge on large-scale cyber-attacks as being crucial for the composition of next generation data-driven cybersecurity defence applications.
Hatem A. Almazarqi, Mathew Woodyard, Troy Mursch, Dimitrios P. Pezaros, Angelos K. Marnerides
GLOBECOM1
2021 Profiling IoT Botnet Activity in the Wild
abstract
Undoubtedly, the Internet of Things (IoT) contributes significantly to daily mission-critical processes underpinning a number of socio-technical systems. Conversely, its rapid adoption has extensively broadened the cyber-threat landscape by virtue of low-cost IoT devices that are manufactured and deployed with minimal security. Evidently, vulnerable IoT devices are utilised by attackers to participate into Internet-wide botnets in order to instrument large-scale cyber-attacks and disrupt critical Internet services. Since the 2016 outbreak of the first IoT Mirai botnet there has been a continuous evolution of Mirai-like variants. Tracking these botnets is challenging due to their varying structural characteristics, and also due to the fact that malicious actors continuously adopt new evasion and propagation strategies. This work provides a new measurement study highlighting specific behavioural properties of Mirai-like botnets in terms of their propagation. We provide a comprehensive analysis conducted on real Cyber Threat Intelligence (CTI) feeds gathered for a period of 7 months from globally distributed attack honeypots and pinpoint the evolutionary port scanning patterns, targeted vulnerabilities and preferred services pursued by Mirai-like botnets. We identify the most frequently active Mirai-like malware binaries and we are the first to report the evolution of a new, P2P-based variant. In parallel, we provide evidence related to the lack of vendor-specific patching through highlighting unpatched vulnerabilities. Moreover, we pinpoint the inadequacy of widely used IP blacklisting databases to timely list malicious IP addresses. Thus, arguing in fair of integrating honeypot information from diverse Internet vantage points within the design of next generation botnet defence mechanisms.
Hatem A. Almazarqi, Angelos K. Marnerides, Troy Mursch, Mathew Woodyard, Dimitrios P. Pezaros
GLOBECOM1