Brierley, Calvin, Huang, Yuxiang, Wang, Yichao, Pope, James, Oikonomou, George, Arief, Budi (2026) Turbulence: Ransomware Proof of Concept for Resource-Constrained IoT Devices. In: 23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA '26). (In press) (KAR id:114624)
|
PDF
Author's Accepted Manuscript
Language: English |
|
|
Download this file (PDF/943kB) |
Preview |
| Request a format suitable for use with assistive technology e.g. a screenreader | |
Abstract
The “Internet of Things” (IoT) is a term used to describe smart devices that are capable of connecting to a network. IoT devices can take many forms, such as cameras, televisions, or home assistants, and are often designed to perform specific tasks. While they only require limited processing power to achieve their intended purpose, their connected nature means they are still vulnerable to attack. Most IoT-based malware is designed to infect devices using General Purpose Operating Systems, such as Linux. Malware targeting “constrained” IoT devices, which have lower hardware specifications and implement bare-metal firmware or a Real Time Operating System, are significantly less common, as they present a number of challenges that can hinder malware development. In this work, we identify these challenges and assess the viability of implementing functional ransomware that targets constrained IoT devices. We then test our findings by developing a ransomware Proof of Concept capable of locking a target system and spreading throughout a network. Finally, we analyse the ransomware’s performance against an intentionally vulnerable testbed to identify the requirements and limitations of – as well as potential countermeasures against – ransomware targeting constrained IoT devices.
| Item Type: | Conference proceeding |
|---|---|
| Uncontrolled keywords: | Ransomware, Internet of Things, Constrained Device, Proof of Concept, Malware |
| Subjects: | Q Science > QA Mathematics (inc Computing science) |
| Institutional Unit: |
Schools > School of Computing Institutes > Institute of Cyber Security for Society |
| Former Institutional Unit: |
There are no former institutional units.
|
| Funders: | Engineering and Physical Sciences Research Council (https://ror.org/0439y7842) |
| Depositing User: | Budi Arief |
| Date Deposited: | 08 May 2026 16:25 UTC |
| Last Modified: | 08 May 2026 16:25 UTC |
| Resource URI: | https://kar.kent.ac.uk/id/eprint/114624 (The current URI for this page, for reference purposes) |
- Link to SensusAccess
- Export to:
- RefWorks
- EPrints3 XML
- BibTeX
- CSV
- Depositors only (login required):

https://orcid.org/0000-0001-8766-822X
Total Views
Total Views