White-Hat Worm to Fight Malware and Its Evaluation by Agent-Oriented Petri Nets †

Sensors (Basel, Switzerland)

MDPI

IoT, cybersecurity, malware, DDoS, bot, botnet, Petri net

Abstract

A new kind of malware called Mirai is spreading like wildfire. Mirai is characterized by targeting Internet of Things (IoT) devices. Since IoT devices are increasing explosively, it is not realistic to manage their vulnerability by human-wave tactics. This paper proposes a new approach that uses a white-hat worm to fight malware. The white-hat worm is an extension of an IoT worm called Hajime and introduces lifespan and secondary infectivity (the ability to infect a device infected by Mirai). The proposed white-hat worm was expressed as a formal model with agent-oriented Petri nets called PN $2$ . The model enables us to simulate a battle between the white-hat worm and Mirai. The result of the simulation evaluation shows that (i) the lifespan successfully reduces the worm’s remaining if short; (ii) if the worm has low secondary infectivity, its effect depends on the lifespan; and (iii) if the worm has high secondary infectivity, it is effective without depending on the lifespan.

Author and article information

19 January 2020
This paper is an extended version of our paper published in Yamaguchi, S. Modeling and Evaluation of IoT Worm with Lifespan and Secondary Infectivity by Agent-Oriented Petri Net PN $2$ . In Proceeding of the IEEE 6th International Conference on Consumer Electronics – Taiwan (IEEE 2019 ICCE-TW), Yilan, Taiwan, 20–22 May 2019.

