This paper discusses a Security Information and Event Management (SIEM)-based system designed to detect and mitigate DDoS attacks originating from IoT botnets due to their vulnerabilities. It presents a prototype implementation that effectively identifies and blocks malicious traffic from compromised IoT devices by monitoring specific packet types. The authors highlight the rising threat posed by IoT botnets and the necessity for robust detection mechanisms in today's cybersecurity landscape.
Related topics: