Skip to main content
Kent Academic Repository

Turbulence: Ransomware Proof of Concept for Resource-Constrained IoT Devices

Brierley, Calvin, Huang, Yuxiang, Wang, Yichao, Pope, James, Oikonomou, George, Arief, Budi (2026) Turbulence: Ransomware Proof of Concept for Resource-Constrained IoT Devices. In: 23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA '26). (In press) (KAR id:114624)

Abstract

The “Internet of Things” (IoT) is a term used to describe smart devices that are capable of connecting to a network. IoT devices can take many forms, such as cameras, televisions, or home assistants, and are often designed to perform specific tasks. While they only require limited processing power to achieve their intended purpose, their connected nature means they are still vulnerable to attack. Most IoT-based malware is designed to infect devices using General Purpose Operating Systems, such as Linux. Malware targeting “constrained” IoT devices, which have lower hardware specifications and implement bare-metal firmware or a Real Time Operating System, are significantly less common, as they present a number of challenges that can hinder malware development. In this work, we identify these challenges and assess the viability of implementing functional ransomware that targets constrained IoT devices. We then test our findings by developing a ransomware Proof of Concept capable of locking a target system and spreading throughout a network. Finally, we analyse the ransomware’s performance against an intentionally vulnerable testbed to identify the requirements and limitations of – as well as potential countermeasures against – ransomware targeting constrained IoT devices.

Item Type: Conference proceeding
Uncontrolled keywords: Ransomware, Internet of Things, Constrained Device, Proof of Concept, Malware
Subjects: Q Science > QA Mathematics (inc Computing science)
Institutional Unit: Schools > School of Computing
Institutes > Institute of Cyber Security for Society
Former Institutional Unit:
There are no former institutional units.
Funders: Engineering and Physical Sciences Research Council (https://ror.org/0439y7842)
Depositing User: Budi Arief
Date Deposited: 08 May 2026 16:25 UTC
Last Modified: 08 May 2026 16:25 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/114624 (The current URI for this page, for reference purposes)

University of Kent Author Information

  • Depositors only (login required):

Total unique views of this page since July 2020. For more details click on the image.