<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Technique for IoT Cyberattacks Detection Based on the Energy Consumption Analysis</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Kira Bobrovnikova</string-name>
          <email>bobrovnikova.kira@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sergii Lysenko</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Peter Popov</string-name>
          <email>p.t.popov@city.ac.uk</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmytro Denysiuk</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii Goroshko</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>City University of London</institution>
          ,
          <addr-line>Northampton Square, London EC1V 0HB</addr-line>
          ,
          <country country="UK">United Kingdom</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Khmelnytskyi National University</institution>
          ,
          <addr-line>Institutska str., 11, Khmelnytskyi, 29016</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>- Today Smart Home is a system for managing the basic life support processes of both small systems (commercial, office premises, apartments, cottages) and large automated complexes (commercial and industrial complexes). One of the important tasks to be solved by the concept of a modern Smart Home is the problem of preventing the malware spread and the usage of IoT infrastructure. One of the possible approaches for abnormal behavior of the IoT devices and IoT cyberattack detection is the monitoring of the energy consumption. Thus, an effective control and monitoring of heating, ventilation, air conditioning, more efficient use of traditional appliances and the introduction of energy-efficient equipment in the building are important to ensure and decision making in the terms of cybersecurity. In addition, improving the efficiency of energy management and monitoring is the approach to increasing effectiveness of the IoT cyberattack detection in the IoT infrastructure. The paper presents a technique for IoT attacks detection based on the IoT devices energy consumption analysis, which take into account the energy consumption related user's preference modes. With aim to improve the accuracy of IoT cyberattacks detection and localize the IoT malware on these IoT devices the IoT software opcodes sequences analysis is applied. The proposed approach allows detecting the performing of the IoT devices such attacks, for example, as DoS/DDoS with high efficiency, at a level of about 99.88% and localizing malicious IoT software on these devices with accuracy of about 99.66%.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Internet of things</kwd>
        <kwd>cyberattack</kwd>
        <kwd>DDoS</kwd>
        <kwd>malware detection</kwd>
        <kwd>energy consumption</kwd>
        <kwd>sequential pattern mining</kwd>
        <kwd>opcodes analysis</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The Internet of Things and Smart Home conception have become an important part of modern
society. In the other hand, the growing number of IoT devices, which are often released without any
security features, makes them a desirable target for cybercriminals [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ].
      </p>
      <p>
        Unprotected IoT devices join the ranks of botnets that are most often used to launch DDoS attacks
or as VPN exit nodes. Cryptomining is another popular way to monetize compromised IoT devices.
Since the limited battery capacity of smartphones does not allow them to be used for profit, that smart
TVs, set-top boxes and other IoT devices are popular with cybercriminals. Almost any smart IoT
device connected to the Internet, for example, gas, water and electricity meters, can become objects of
interest for cybercriminals [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>
        According to forecasts of the GSMA [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], by 2025 the number of connected IoT devices will
double and reach almost 25 billion worldwide, and as the popularity of IoT increases, the risk of
cyberattacks will increase.
      </p>
      <p>
        Today, the efficient use of energy resources is another one of the most important tasks. At the
same time, almost a third of the total energy consumption is made up of certain losses, i.e. the energy
is consumed not on purpose [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Further growth in energy consumption is also expected. Increasing
attention to the problems of energy efficiency and energy saving also contributes to the development
of the concept of a modern smart home. Furthermore, if at first this concept was to connect sensors,
devices and devices over a network for the purpose of remote monitoring, access and control of the
living environment and provide the necessary services to users, then at the present stage it also
involves the optimal use of energy in buildings, as well as the malware and IoT cyberattack detection
in Smart Home infrastructure.
      </p>
      <p>
        IoT devices energy consumption monitoring is a possible way to detect those performing attacks,
which require significant energy consumption [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], for example DDoS and cryptomining. In addition,
energy consumption analysis based approach is more secure in cases the kernel of the device is
already compromised, so far as once the device is compromised, the data integrity cannot be
guaranteed.
      </p>
    </sec>
    <sec id="sec-2">
      <title>2. Related works</title>
      <p>
        Today, scientific sources widely present various approaches aimed at ensuring energy efficiency
and energy saving in the smart home system [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref6 ref7 ref8 ref9">6-12</xref>
        ]. In [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] it is noted that in recent years the main
direction of energy efficiency policy has been to promote the use of more efficient appliances and
components. However, home automation control plays an important role in efficient and sustainable
operation: (1) by identifying and eliminating energy losses; (2) by using energy only in the right
amount, place and only at the time when it is needed; (3) by exercising correct control of the
functional level of the system for correct application in the right place.
      </p>
      <p>
        Today, there is also a shortage of operating systems that would provide the ability to integrate the
devices that make up the smart home environment. The problem stems from the fact that smart
devices are based on self-service modules and use independent IoT platforms developed by various
manufacturers. This leads to the need to control each device separately, which reduces the energy
efficiency of the home and increases the amount of traffic on the network. To solve this problem, an
integrated control system is proposed in [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], which combines IoT devices into a single system.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] an analysis of the benefits and risks of smart home technologies from different points of
view is carried out. One of the risks is the lack of attention of developers in the field of smart home
technologies to measures to increase consumer confidence in data security and privacy.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] a various approaches to intelligent control of home systems in order to reduce energy
consumption are considered. One such approach is feed-forward control. Such a system directly
compensates for interference factors such as external temperature, wind, solar radiation, internal heat
gain by measuring interference factors in real time to implement appropriate measures based on
known parameters.
      </p>
      <p>
        Another approach is model-based predictive control (MPC) [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], which is a structured approach
that predicts future system behavior based on models and adjusts the system accordingly. Fuzzy logic
control does not require a complex mathematical model to control the system and can be based
directly on the quality user experience. The disadvantage of this approach is the complexity of
determining the optimal rules and membership functions for such systems [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
      </p>
      <p>
        Another well-known approach for building control systems for a home is artificial neural networks
(ANNs), which are widely used to model and predict energy use in buildings. Artificial neural
networks are capable of simulating non-linear processes, constantly adapting to new data and learning
from this data in order to solve complex problems [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
      </p>
      <p>
        Also known are hybrid approaches based on the use of fuzzy logic and artificial neural networks,
combining the advantages of both approaches - imitation of human logic and the ability to learn.
Adaptive neuro-fuzzy (ANF) systems implement neural network learning algorithms for tuning
membership functions in a fuzzy system. In a control system based on agents, which are virtual or
physical modules, agents cooperate with the environment by perceiving and influencing parameters
using artificial intelligence [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. Such systems are able to balance energy consumption, cost and
comfort by measuring and interacting with the environment and controlling heating, ventilation and
air conditioning systems and electrical appliances.
      </p>
      <p>
        The study [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] analyzed known home energy management systems in order to identify key
differences in their functionality and quality, and identified opportunities for energy savings (both
behavioral and operational). It is also noted that in many cases, potential benefits related to
convenience, comfort or safety can limit the implementation of energy saving scenarios.
      </p>
      <p>
        Also are known a number of approaches based on monitoring the IoT devices energy consumption
devoted to detecting IoT cyberattacks. In the [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] quantitatively studied the impact of DDoS and
EDDoS attacks on smart home IoT devices and on them energy consumption and the underlying
reasons for these devices’ various response types were analyzed.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] a machine learning based method wish allows to detect ransomware attacks by monitoring
energy consumption patterns for different processes of Android devices was presented.
      </p>
      <p>
        In the paper [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ] a dynamic technique to detect malware on Android platform was proposed. This
technique uses a set of 38 energy related features belonging to three different categories: CPU,
Memory and Network, which can be symptomatic of abnormal battery consumption.
      </p>
      <p>
        The paper [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] is focused on malware detection using power consumption and network traffic data
collected. With this aim seven power-based and eighteen network traffic-based features were applied.
      </p>
      <p>
        In the work [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ] an IoT attack detection framework based on energy consumption analysis was
proposed. The proposed framework processes the energy consumption of IoT devices and classifies
the attack status (not only cyberattacks, but also physical attacks) of the monitored devices. A
twostage strategy is proposed: applying a short time window for rough attack detection, and a long time
window to the fine attack detection.
      </p>
      <p>
        Nonetheless, in the paper [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] energy consumption analysis approaches were evaluated and
concluded that these approaches are not applicable to such devices as, for examples, smartphones.
This is due to the fact that the typical energy consumption of such devices is varies quite a lot in
practice, as well due to the noise introduced into the system by unpredictable user and environment
interactions. These nuances will lead to a lot of false alarms. Also empirical tests were conducted and
they showed that the additional power consumed by both artificial and real-world malicious
applications is too small to be detectable with the mean error rates of state-of-the art measurement
tools. However, it was noted, that such attacks as DDoS can be detected by analyzing the energy
consumption of similar devices.
      </p>
      <p>IoT devices total energy consumption monitoring cannot provide an answer to the question of
localizing malware as a source of IoT cyberattack. One of the possible approaches to identifying
suspicious programs with aim its localization is to analyze programs opcodes.</p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ] an approach based on analysis opcode N-gram sequences to classifying ransomware was
proposed. To select feature N-grams Term frequency-Inverse document frequency (TF-IDF) for each
of them is calculated. Of the TF values of the feature N-grams the feature vectors are constructed and
by machine-learning methods are processed to perform ransomware classification.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ] a deep learning based technique for Internet Of Battlefield Things malware detection which
uses class-wise selection of opcodes sequence as a feature for classification task was presented. The
opcodes are transmuted into a vector space and a graph of selected features was created for each
sample. To classify malicious and benign application a deep Eigen space learning approach was
applied.
      </p>
      <p>
        In the paper [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] combining sequential pattern mining algorithm with machine learning techniques
to detect most frequent opcodes sequences of malicious IoT applications was applied.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ] a multi-view learning method that uses multiple views including opcodes, bytecodes,
header information, permission, attacker’s intent and API call to detection malware. With aim to
detection optimization in different environment the proposed system automatically assigns different
weights to these views.
      </p>
      <p>
        In the paper [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ] a malware detection approach based on the opcodes analysis by using the
evolutionary algorithm. According this approach the label of suspicious instance is defined based on
the most similar graph obtained from the evolutionary algorithm with each family of malware and
benign applications.
      </p>
      <p>
        Despite the large number of different developed methods for detecting and preventing cyberattacks
and malware, as well as newel data analysis approaches [
        <xref ref-type="bibr" rid="ref28 ref29 ref30 ref31 ref32 ref33 ref34 ref35 ref36 ref37">28-44</xref>
        ], IoT devices is still incredibly
vulnerable and suffered a wide range of cyberattacks and their financial and public relations
consequences. Therefore, there is a need to develop new approaches for the IoT malware and IoT
cyberattack detecting.
      </p>
    </sec>
    <sec id="sec-3">
      <title>Technique for IoT cyberattacks detection</title>
      <p>consumption analysis
based
on the
energy</p>
      <p>The proposed technique for IoT cyberattacks detection uses analysis of the IoT devices energy
consumption footprints and also applies analysis of the IoT software opcodes sequences to improve
the accuracy of IoT attacks detection and localize the IoT malware on these IoT devices.</p>
      <p>To effectively build IoT devices energy consumption footprints, it is necessary to take into account
the different energy consumption related user preference modes (let denote it as UPM) for HVAC
systems (Heating, Ventilation, &amp; Air Conditioning), lightening and functioning of different IoT
devices. Let us denote the set of IoT user’s preference modes for certain IoT device as</p>
      <p>Pd = { pi}iN=1P ,
where d – the certain IoT device, d ∈ D, D ={di}iL=1 – the set of IoT devices in the IoT network, L –
the amount number of IoT devices in the network;
pi ∈{"very low", "low", "normal ", "high", "very high"} and define the energy consumption related UPM,
such as temperature, lighting, humidity, air quality modes etc. and functioning modes of the different
IoT devices d ;
NP – the number of UPM for certain IoT device, NP ≥ 1.</p>
      <p>Also let define the energy consumption control function ϕ , which keep up the energy
consumption of the IoT device according a given UPM as
ϕ : {d | nd ≠ nd, p} → nd, p ,
(1)
(2)
where nd – the current energy consumption of the IoT device d ;
nd , p – the energy consumption of the IoT device d in certain user preference mode p .</p>
      <p>The proposed technique consists of two stages: learning and detection stages. In turn learning stage
includes the energy consumption analysis and the opcodes sequences analysis. The steps of the
learning stage of the energy consumption analysis are presented following.</p>
      <p>1. The IoT devices energy consumption footprints for different energy consumption related
user’s preference modes in the absence of the IoT cyberattacks building, normalization and
labelling.
2. The IoT devices energy consumption footprints for different energy consumption related
user’s preference modes in the presence of the IoT cyberattacks building, normalization and
labelling.
3. Labeled and unlabeled data matrix of the IoT devices energy consumption footprints building.
4. Semi-supervised learning of the fuzzy c-means classifier by using the labeled data matrix of
the IoT devices energy consumption footprints.
5. Testing of the fuzzy c-means classifier by using unlabeled data matrix of the IoT devices
energy consumption footprints.
6. Evaluating of the effectiveness of the energy consumption analysis.</p>
      <p>As noted above, to improve the accuracy of IoT attacks detection based on energy consumption
analysis and localize the IoT malware on IoT devices opcodes sequences analysis is applied. The
steps of the learning stage of the opcodes sequences analysis are presented following.
1. The assembly representation extraction from the benign and malicious IoT binary executable.
2. The opcodes maximal sequential patterns (MSP) mining in the all binary executable assembly
representation.
3. The MSP selection for constructing feature vectors.
4. The relevance calculation for each of the selected MSP.
5. The feature vectors of opcodes MSP relevance construction and labelling for each binary
executable assembly representation.
6. Labeled and unlabeled data matrix of the feature vectors of MSP building.
7. Semi-supervised learning of the fuzzy c-means classifier by using the labeled data matrix of
the feature vectors of MSP.
8. Testing of the fuzzy c-means classifier by using unlabeled data matrix of the feature vectors
of MSP.
9. Evaluating of the effectiveness of the opcodes sequences analysis.</p>
      <p>On the detection stage of the proposed technique the energy consumption of IoT devices is
measured and analyzed. If the IoT device has an abnormally high energy consumption, this may
indicate that it has carried out cyberattacks. But IoT device total energy consumption monitoring
cannot provide an answer to the question of localizing malware on this device as a source of IoT
cyberattack. Therefore, it is necessary to analyze suspicious software on the IoT device in order to
localize it. So identifying the suspicious programs with aim its localization software opcodes
sequences analysis was performed. With this aim opcodes maximal sequential patterns, MSP, mining
in the assembly representation of suspicious binary executable is performed. For obtained MSP their
relevance calculated and feature vectors for these suspicious software is built and analyzed.</p>
      <p>The scheme of the technique for IoT attacks detection based on the energy consumption analysis
presented in Fig. 1.</p>
      <p>Let us consider the main steps of the learning stage of technique for IoT cyberattacks detection
based on the energy consumption analysis.</p>
    </sec>
    <sec id="sec-4">
      <title>3.1. Energy consumption footprints building</title>
      <p>With aim the IoT cyberattacks detection at the learning stage the energy consumption of each IoT
device in the IoT network for different IoT UPM in the absence of IoT cyberattacks is measured at a
certain interval and at equal sub-intervals of time. Based on these measurements, the set of IoT
devices energy consumption footprints Nd, p are constructed, part of them labelled as “normal”
footprints and entered into the labeled data matrix Dl , rest of them entered on the unlabeled data
matrix Dunl (Fig. 2).</p>
      <p>
        Let us describe the energy consumption footprints in the absence of IoT cyberattacks taking into
account the set of UPM as
where nd , p,i – the normalized measurement of the whole IoT device d energy consumption at a
point in time in the absence of IoT cyberattacks for IoT user’s preference mode p , nd, p,i ∈[
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ] ,
where 0 indicates lack of energy consumption and 1 presents the maximum of energy consumption in
the absence of IoT cyberattacks;
K – the number of measurements in the time interval.
      </p>
      <p>Nd, p = (nd, p,i )iK=1 ,
(3)
(4)</p>
      <p>Also the IoT devices energy consumption footprints in the presence different types of IoT
cyberattacks with taking into account different IoT UPM should be built. With this aim these IoT
devices were infected with malicious IoT software, which were able to carry out these types of IoT
cyberattacks. After that the energy consumption of each IoT device for different IoT UPM in the
presence of IoT cyberattacks is measured at a certain interval and at equal sub-intervals of time. Then
based on these measurements, the set of IoT devices energy consumption footprints in the presence of
IoT cyberattacks Ad, p,t are constructed, part of them labelled as energy consumption footprints for
certain type of IoT cyberattacks and entered into the labeled data matrix Dl , rest of them entered on
the unlabeled data matrix Dunl (Fig. 2).</p>
      <p>Let us describe the set of IoT devices energy consumption footprints in the presence of IoT
cyberattacks taking into account the set of UPM as</p>
      <p>
        Ad, p,t = (ad, p,t,i )iK=1 ,
where ad , p,t,i – the normalized measurement of IoT device energy consumption at a point in time in
the presence of certain type cyberattacks, ad, p,t,i ∈[
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ] , where 0 indicates lack of energy
consumption and 1 presents the maximum of energy consumption in the presence of IoT cyberattacks;
t ∈T – the type of IoT cyberattacks, T – the set of IoT cyberattacks type;
K – the number of measurements in the time interval.
      </p>
      <p>After that the semi-supervised learning of the fuzzy c-means classifier by using the labeled data
matrix Dl of energy consumption footprints Nd, p and Ad, p,t are performed.</p>
      <p>The main particularities of applied classification algorithm are described below in Section 3.3.</p>
      <p>To evaluate the effectiveness of the IoT cyberattack detection based on energy consumption
testing the fuzzy c-means classifier by using unlabeled data matrix Dunl of energy consumption
footprints was performed.</p>
    </sec>
    <sec id="sec-5">
      <title>3.2. Feature vectors of opcodes MSP relevance building</title>
      <p>With aim the IoT devices opcodes sequences analysis at the learning stage the assembly
representation from the benign and malicious IoT binary executable examples are extracted. From
these assembly representations opcodes MSP are extracted by applying of sequential patterns mining
algorithm.</p>
      <p>For each MSP the inverse document frequency value, IDF, which reduces the weight of commonly
used MSP, is calculated as</p>
      <p>IDF (MSP, Z ) = log</p>
      <p>| Z |
| {zi ∈ Z | MSP ∈ zi} |</p>
      <p>,</p>
      <p>R =))iN=1R (IDF (MSPi , Z , IDF (MSPi , Z ) &lt; IDF (MSPi+1, Z ) ,
where NR – the total number of different MSP.</p>
      <p>To assess the MSP relevance for each MSP weighted term frequency (WTF) values [45] are
calculated as following.</p>
      <p>Weighted term frequency (WTF) is the result of weighting the term frequency, TF with the
relevance of each opcode o and are computed as the product of sequence frequency and the calculate
weight of every opcode o in the sequence MSP:
where | Z | – the total number of the executables z ∈ Z , Z =Zb ∪ Zm , were Zb – set of benign IoT
software, Zm – set of malicious IoT software;
| {zi ∈ Z | MSP ∈ zi} | – the number of the executables z in the set Z , in which appears MSP .</p>
      <p>To determine the order of MSP in the feature vectors, the MSP are sorted ascending values
IDF (MSP, Z ) :
(5)
(6)
(7)
(8)
WTF (MSP, z) =(MSP, TF z) ×</p>
      <p>∏
o∈MSP 100</p>
      <p>W (o)
where W (o) – the calculated weight, by means of mutual information gain, for the opcode o ;
TF (MSP, z) – the MSP frequency measure within the IoT software.</p>
      <p>Term frequency, TF (MSP, z) , assessed the importance of a MSP within an IoT software executable
and can be calculated as</p>
      <p>TF (MSP, z) =</p>
      <p>fMSP,z
∑ MSP'∈z fMSP',z
where fMSP,z – the number of times the MSP appears in an executable z ; ∑ MSP'∈z fMSP',z – the
total number of opcodes sequences in the executable z .</p>
      <p>The Mutual Information I (F; Ψ) , on which the calculation W (o) is based, is measure of the
statistical dependence of the two variables, in this case they are the single opcode o and whether or
not the software was malware:
where F – the opcode frequency;
Ψ – the class of the file;
p( f ,ψ ) – is the joint probability distribution function of F and Ψ ;
p( f ) and p(ψ ) – the marginal probability distribution functions of F and Ψ .</p>
      <p>From obtained for each MSP WTF value for each IoT software feature vector of opcodes MSP
relevance is built. In the process vectors, whose length is greater than the median length H of the all
obtained vectors, are truncated. Vectors, whose length is less than H , are padded with zeros.</p>
      <p>Let us denote feature vector of opcodes MSP relevance as</p>
      <p>Sd ,ap = (sd ,ap,i )iH=1 ,
where sd ,ap,i – the IoT software opcodes MSP relevance;
H – the number of IoT software opcodes MSP.</p>
      <p>The part of constructed vectors labelled respectively as “benign” or “malicious” and entered into
the labeled data matrix Wl , rest of them entered on the unlabeled data matrix Wunl (Fig. 3).
 p( f ,ψ ) 
I (F; Ψ) =∑ ∑ p( f ,ψ ) log   ,
ψ ∈Ψ f ∈F  p( f ) × p(ψ ) 
(9)
(10)</p>
    </sec>
    <sec id="sec-6">
      <title>3.3. Data classification</title>
      <p>
        With aim to detect a IoT cyberattacks in proposed approach the semi-supervised fuzzy c-means
classifier was applied. The advantage of the using fuzzy clustering is the weakening of the
requirement for unambiguous clustering of objects, it becomes possible due to the applying of
membership functions to the fuzzy clusters, that take values in the interval [
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ]. This allows
increasing the accuracy and information completeness of the clustering results in cases where
clustering objects are located at the boundaries of the clusters.
      </p>
      <p>The applying of semi-supervised learning allows specifying the initial centers of clusters, which
improves the quality of clustering results. The initial centers of the clusters were determined on the
basis of a training sample, the volume of which was 10% of the data collected for analysis.</p>
      <p>As clustering objects are the IoT devices energy consumption footprints. But instead of the
Euclidean distance, which is used in the basic c-means algorithm, for IoT devices energy consumption
footprints clustering as a distance measure the dynamic time warping, DTW, was applied.</p>
      <p>The use of Euclidean distance has a significant drawback: if two time series are the same, but one
of them is slightly displaced in time (along the time axis), then the Euclidean metric may consider that
the series are different from each other.</p>
      <p>The DTW algorithm was introduced in order to overcome this disadvantage and provide a
measurement of the distance between rows, without paying attention to both global and local shifts on
the timeline.</p>
      <p>
        The result of the IoT devices energy consumption footprints clustering is a fuzzy partition matrix
C , where each element of the matrix сij determines the degree of belonging of the i -th element (the
energy consumption footprint of IoT device) to the j -th cluster: C =cij  ,cij ∈[
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ] ,i =1,ϒ, j =1,Ω ,
∑ cij = 1 , where ϒ – the number of energy consumption footprints, Ω – the number of the
j= 1,Ω
clusters. Thus, each clustering objects with a certain degree of affiliation belongs to each of the Ω
clusters, each of which denotes normal energy consumption in a specific user mode or increased
power consumption, indicating an attack.
      </p>
      <p>For the feature vectors of opcodes MFP relevance classification instead of the Euclidean distance
the Mahalanobis distance was used. It makes it possible to form clusters in the form of hyperelipsoids
with axes oriented in arbitrary directions, which allows taking into account the possible presence of
outliers in the classified data, that is, observation results that stand out from the general sample.</p>
      <p>
        The result of clustering is a fuzzy partition matrix S , where each element of the matrix sij
determines the degree of belonging of the i -th element of the set of clustering objects to the j -th
cluster: S =sij  ,sij ∈[
        <xref ref-type="bibr" rid="ref1">0,1</xref>
        ] ,i =1,Χ, j =1,Π ,
∑ sij = 1 , where Χ – the number of the feature vectors of
j= 1,Π
opcodes MFP relevance, Π – the number of the clusters. Thus, each feature vector with a certain
degree of affiliation belongs to each of the Π clusters, each of which denotes benign software or
certain type of malware.
      </p>
      <p>Let's take λ as the threshold values of clustering object belonging to the cluster, at which the
clustering object is considered as malicious. If cij ≥ λ , then the clustering object belongs to a j
cluster.</p>
      <p>Also let us denote the set of all clusters as Ψ = Ψ N ∪ Ψ A , where Ψ N is a subset of clusters that
correspond to benign clustering objects, Ψ A is a subset of clusters that correspond to malicious
clustering objects.</p>
    </sec>
    <sec id="sec-7">
      <title>4. Experimental results</title>
      <p>In order to assess the effectiveness of the proposed approach, a number of experiments were
carried out. The ARM platform was chosen as the target IoT platform for the experiments, since it is
one of the most common IoT platforms. Thus variety of ARM-based IoT devices (such as smart TVs,
camcorders and routers) have been used. Also 284 corresponding samples of benign software from
[46] and 297 malicious software samples [47], including 91 polymorphic malware samples were
generated from these malware using the open-source polymorphic malware creation tool [48], have
been used.</p>
      <p>The IoT devices used in the experiments were infected with malicious software and were used to
carry out DDoS attacks on a target on an isolated network. During the experiments, the energy
consumption footprints of these IoT devices were obtained under normal operating conditions, as well
as when these IoT devices carry out cyberattacks. Each energy consumption footprint was obtained by
taking measurements after 0.5 s. within 3 minutes when the IoT device is performing an attack and
normal operation. A total of 1253 energy consumption footprints of both in the presence of attacks
and normal functioning IoT devices were built.</p>
      <p>Also, using the proposed approach, opcodes sequences were extracted and analyzed from
malicious software samples that carried out these DDoS attacks. These software samples were
disassembled by using the IDA Pro [49] to obtain its opcodes. For opcodes sequences mining
hashbased partition sequential pattern mining algorithm (HPSPM) [50] was used.</p>
      <p>Some of these data (about 10%) were used for training, the rest of the data were used as testing
data to assess the effectiveness of the proposed approach. For the purpose of classifying the malicious
samples Support Vector Machine (SVM) [51, 52], K Nearest Neighbor (KNN), Decision Tree,
Random Forest and Semi-Supervised Fuzzy C-Means [53] classifiers were applied.</p>
      <p>In order to assess the effectiveness of the proposed approach, the following metrics were applied.</p>
      <p>Accuracy is as a statistical measure which defined the proportion of correct predictions (both true
positives and true negatives) among the total number of cases examined:</p>
      <p>ACC = TP + TN , (11)</p>
      <p>TP + TN + FP + FN
where TP (true positive) – correctly classified malware samples;
TN (true negative) – correctly classified samples are benign;
FN (false negative) – malicious samples, erroneously classified as benign;
FP (false positive) – benign samples, erroneously classified as malicious.</p>
      <p>Another measure of a test's accuracy is F-measure (or balanced F-score, F1 score), which defined
as the harmonic mean of precision and recall:</p>
      <p>The results of the experiments showed a high efficiency of IoT cyberattacks detection based on the
energy consumption analysis (Table 1). At the same time, as it is showed from the Table 2, the
analysis of the opcodes sequences of suspicious software will allow localizing the program on the IoT
device, which is the source of the IoT cyberattack, with high efficiency. As can be seen from the
experimental results, the highest efficiency was achieved using Semi-Supervised Fuzzy C-Means
clustering.</p>
    </sec>
    <sec id="sec-8">
      <title>5. Conclusions</title>
      <p>Thus, taking into account, that high IoT device’s energy consumption may indicate that the IoT
device is carrying out a cyberattacks, which require increased energy consumption, a new technique
for IoT attacks detection based on the IoT devices energy consumption analysis was proposed. These
technique take into account the energy consumption related user’s preference modes. Therefore with
aim cyberattacks detection the energy consumption of IoT devices is measured and analyzed. For the
purpose of localizing the software on the IoT device that performs the cyberattacks these software
opcodes analysis was performed. With this aim opcodes maximal sequential patterns, MSP, mining in
the assembly representation of suspicious binary executable is performed. For obtained MSP their
relevance calculated and feature vectors for this suspicious software is built and analyzed.</p>
      <p>The experimental results show that the proposed approach allows detecting the performing by the
IoT devices such attacks, as, for example, DoS/DDoS, with high efficiency, at a level of about
99.88% and localizing malicious IoT software on these devices with accuracy of about 99.66%.
6. References
Advanced Trends in Information Theory, ATIT 2019 – Proceedings (2019) 326-335.
doi:10.1109/ATIT49449.2019.9030481
[38] S. Lysenko, K. Bobrovnikova &amp; O. Savenko, A botnet detection approach based on the clonal
selection algorithm. In 2018 IEEE 9th International Conference on Dependable Systems,
Services and Technologies (DESSERT). IEEE (2018) 424-428.
[39] R. Leizerovych, G. Kondratenko, I. Sidenko and Y. Kondratenko, "IoT-complex for Monitoring
and Analysis of Motor Highway Condition Using Articial Neural Networks," 2020 IEEE 11th
International Conference on Dependable Systems, Services and Technologies (DESSERT), Kyiv,
Ukraine (2020) 207-212. doi:10.1109/DESSERT50317.2020.9125004.
[40] O. Pomorova, O. Savenko, S. Lysenko &amp; A. Kryshchuk, Multi-agent based approach for botnet
detection in a corporate area network using fuzzy logic. In International Conference on Computer
Networks. Springer, Berlin, Heidelberg (2013) 146-156.
[41] A. Drozd, M. Al-Dhabi, S. Antoshchuk, A. Martinyuk &amp; M. Drozd, Models and methods
checking mantissas by inequalities for on-line testing of digital circuits in critical applications. In
2017 IEEE East-West Design &amp; Test Symposium (EWDTS). IEEE (2017) 1-5.
[42] S. Lysenko, K. Bobrovnikova, S. Matiukh, I. Hurman &amp; O. Savenko, Detection of the botnets'
low-rate DDoS attacks based on self-similarity. International Journal of Electrical &amp; Computer
Engineering, 2020, 10, 2088-8708.
[43] K. Bobrovnikova, S. Lysenko &amp; P. Gaj, Technique for IoT Cyberattacks Detection Based on</p>
      <p>DNS Traffic Analysis. CEUR, 2623 (2020) 19.
[44] S. Lysenko, O. Savenko, K. Bobrovnikova &amp; A. Kryshchuk, Self-adaptive system for the
corporate area network resilience in the presence of botnet cyberattacks. In International
Conference on Computer Networks. Springer, Cham (2018) 385-401.
[45] I. Santos, F. Brezo, X. Ugarte-Pedrero &amp; P. G. Bringas, Opcode sequences as representation of
executables for data-mining-based unknown malware detection. Information Sciences. 2013,
Vol. 231, pp. 64-82.
[46] Packages Search for Linux and Unix. URL: https://pkgs.org/
[47] VirusTotal. URL: http://www.virustotal.com
[48] Obfuscatoin-for-ARM-disassembled-binary. URL:
https://github.com/darabian/Obfuscatoin-for</p>
      <p>ARM-disassembled-binary
[49] Hex Rays. IDA Pro. URL: https://www.hex-rays.com/products/ida/
[50] R. Millham, I. E. Agbehadji, H. Yang, Pattern Mining Algorithms. In Bio-inspired Algorithms
for Data Streaming and Visualization, Big Data Management, and Fog Computing. Springer,
Singapore (2021) 67-80.
[51] S. Lysenko, K. Bobrovnikova, O. Savenko &amp; A. Kryshchuk, BotGRABBER: SVM-based
selfadaptive system for the network resilience against the botnets’ cyberattacks. In International
Conference on Computer Networks. Springer, Cham (2019) 127-143.
[52] S. Lysenko, K. Bobrovnikova, A. Nicheporuk, R. Shchuka, SVM-based technique for mobile
malware detection. In CEUR Workshop Proceedings (2019) 85-97.
[53] S. Lysenko, O. Savenko &amp; K. Bobrovnikova, DDoS Botnet Detection Technique Based on the
Use of the Semi-Supervised Fuzzy c-Means Clustering. In ICTERI Workshops (2018) 688-695.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>Trend</given-names>
            <surname>Micro</surname>
          </string-name>
          .
          <article-title>Inside the Smart Home: IoT Device Threats</article-title>
          and
          <string-name>
            <given-names>Attack</given-names>
            <surname>Scenarios</surname>
          </string-name>
          . URL: https://www.trendmicro.com/vinfo/it/security/news/internet
          <article-title>-of-things/inside-the-smart-home-iotdevice-threats-and-attack-scenarios.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>McAfee</given-names>
            <surname>Labs Threats</surname>
          </string-name>
          <article-title>Report</article-title>
          . URL: https://www.mcafee.com/enterprise/en-us/assets/reports/rpquarterly-threats-nov-
          <year>2020</year>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <article-title>[3] Global System for Mobile Communications</article-title>
          . URL: https://www.gsma.com/
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>U.S.</given-names>
            <surname>Energy Information</surname>
          </string-name>
          <article-title>Administration (EIA)</article-title>
          .
          <source>International Energy Outlook</source>
          ,
          <year>2019</year>
          . URL: https://www.eia.gov/outlooks/ieo/. - 2.
          <fpage>07</fpage>
          .
          <year>2020</year>
          р.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>J.</given-names>
            <surname>Hoffmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Neumann</surname>
          </string-name>
          , T. Holz,
          <article-title>Mobile malware detection based on energy fingerprints - a dead end?</article-title>
          .
          <source>In International Workshop on Recent Advances in Intrusion Detection</source>
          . Springer, Berlin, Heidelberg (
          <year>2013</year>
          )
          <fpage>348</fpage>
          -
          <lpage>368</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>A. R.</given-names>
            <surname>Al-Ali</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I. A.</given-names>
            <surname>Zualkernan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Rashid</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Gupta</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>M. Alikarar</surname>
          </string-name>
          ,
          <article-title>A smart home energy management system using IoT and big data analytics approach</article-title>
          .
          <source>IEEE Transactions on Consumer Electronics</source>
          .
          <year>2017</year>
          , Vol.
          <volume>63</volume>
          (
          <issue>4</issue>
          ), pp.
          <fpage>426</fpage>
          -
          <lpage>434</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>M. S.</given-names>
            <surname>Hossain</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Rahman</surname>
          </string-name>
          &amp; G. Muhammad,
          <article-title>Cyber-physical cloud-oriented multi-sensory smart home framework for elderly people: An energy efficiency perspective</article-title>
          .
          <source>Journal of Parallel and Distributed Computing</source>
          .
          <year>2017</year>
          , Vol.
          <volume>103</volume>
          , pp.
          <fpage>11</fpage>
          -
          <lpage>21</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>M.</given-names>
            <surname>Isnen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kurniawan</surname>
          </string-name>
          &amp; E.
          <string-name>
            <surname>Garcia-Palacios</surname>
            ,
            <given-names>A-SEM</given-names>
          </string-name>
          :
          <article-title>An adaptive smart energy management testbed for shiftable loads optimisation in the smart home</article-title>
          .
          <source>Measurement</source>
          .
          <year>2020</year>
          , Vol.
          <volume>152</volume>
          ,
          <fpage>107285</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Paredes‐Valverde</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Alor‐Hernández</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. L.</given-names>
            <surname>García‐Alcaráz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. D. P.</given-names>
            <surname>Salas‐Zárate</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. O.</given-names>
            <surname>Colombo‐Mendoza &amp; J. L.</surname>
          </string-name>
          Sánchez‐Cervantes,
          <article-title>IntelliHome: An internet of things‐based system for electrical energy saving in smart home environment</article-title>
          .
          <source>Computational Intelligence</source>
          .
          <year>2020</year>
          , Vol.
          <volume>36</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>203</fpage>
          -
          <lpage>224</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>A. De Paola</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Ferraro</surname>
            ,
            <given-names>G. L.</given-names>
          </string-name>
          <string-name>
            <surname>Re</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Morana &amp; M. Ortolani</surname>
          </string-name>
          ,
          <article-title>A fog-based hybrid intelligent system for energy saving in smart buildings</article-title>
          .
          <source>Journal of Ambient Intelligence and Humanized Computing</source>
          .
          <year>2020</year>
          , Vol.
          <volume>11</volume>
          (
          <issue>7</issue>
          ), pp.
          <fpage>2793</fpage>
          -
          <lpage>2807</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>M.</given-names>
            <surname>Killian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Zauner &amp; M. Kozek</surname>
          </string-name>
          ,
          <article-title>Comprehensive smart home energy management system using mixed-integer quadratic-programming</article-title>
          .
          <source>Applied energy. 2018</source>
          , Vol.
          <volume>222</volume>
          , pp.
          <fpage>662</fpage>
          -
          <lpage>672</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>I.</given-names>
            <surname>Machorro-Cano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Alor-Hernández</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Paredes-Valverde</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Rodríguez-Mazahua</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. L.</given-names>
            <surname>Sánchez-Cervantes</surname>
          </string-name>
          &amp;
          <string-name>
            <given-names>J. O.</given-names>
            <surname>Olmedo-Aguirre</surname>
          </string-name>
          ,
          <article-title>HEMS-IoT: A big data and machine learning-based smart home system for energy saving</article-title>
          .
          <source>Energies</source>
          .
          <year>2020</year>
          , Vol.
          <volume>13</volume>
          (
          <issue>5</issue>
          ),
          <fpage>1097</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>V.</given-names>
            <surname>Fabi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. Spigliantini &amp; S. P.</given-names>
            <surname>Corgnati</surname>
          </string-name>
          ,
          <article-title>Insights on smart home concept and occupants' interaction with building controls</article-title>
          .
          <source>Energy Procedia</source>
          .
          <year>2017</year>
          , Vol.
          <volume>111</volume>
          , pp.
          <fpage>759</fpage>
          -
          <lpage>769</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>H.</given-names>
            <surname>Jo</surname>
          </string-name>
          ,
          <string-name>
            <surname>Y. I. Yoon</surname>
          </string-name>
          ,
          <article-title>Intelligent smart home energy efficiency model using artificial TensorFlow engine</article-title>
          .
          <source>Human-centric Computing and Information Sciences. 2018</source>
          , Vol.
          <volume>8</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>1</fpage>
          -
          <lpage>18</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>C.</given-names>
            <surname>Wilson</surname>
          </string-name>
          , T. Hargreaves,
          <string-name>
            <given-names>R.</given-names>
            <surname>Hauxwell-Baldwin</surname>
          </string-name>
          ,
          <article-title>Benefits and risks of smart home technologies</article-title>
          .
          <source>Energy Policy</source>
          .
          <year>2017</year>
          , Vol.
          <volume>103</volume>
          , pp.
          <fpage>72</fpage>
          -
          <lpage>83</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>L. C.</given-names>
            <surname>Felius</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Dessen</surname>
          </string-name>
          &amp;
          <string-name>
            <given-names>B. D.</given-names>
            <surname>Hrynyszyn</surname>
          </string-name>
          ,
          <article-title>Retrofitting towards energy-efficient homes in European cold climates: a review</article-title>
          .
          <source>Energy Efficiency</source>
          .
          <year>2020</year>
          , Vol.
          <volume>13</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>101</fpage>
          -
          <lpage>125</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>R.</given-names>
            <surname>Ford</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Pritoni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sanguinetti</surname>
          </string-name>
          &amp; B.
          <string-name>
            <surname>Karlin</surname>
          </string-name>
          ,
          <article-title>Categories and functionality of smart home technology for energy management</article-title>
          .
          <source>Building and environment. 2017</source>
          , Vol.
          <volume>123</volume>
          , pp.
          <fpage>543</fpage>
          -
          <lpage>554</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>B.</given-names>
            <surname>Tushir</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Dalal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Dezfouli</surname>
          </string-name>
          &amp; Y. Liu,
          <string-name>
            <surname>A Quantitative</surname>
          </string-name>
          <article-title>Study of DDoS and E-DDoS Attacks on WiFi Smart Home Devices</article-title>
          .
          <source>IEEE Internet of Things Journal</source>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>A.</given-names>
            <surname>Azmoodeh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dehghantanha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Conti</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>K. K. R. Choo</surname>
          </string-name>
          ,
          <article-title>Detecting crypto-ransomware in IoT networks based on energy consumption footprint</article-title>
          .
          <source>Journal of Ambient Intelligence and Humanized Computing</source>
          .
          <year>2018</year>
          , Vol.
          <volume>9</volume>
          (
          <issue>4</issue>
          ), pp.
          <fpage>1141</fpage>
          -
          <lpage>1152</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>F.</given-names>
            <surname>Fasano</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Martinelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Mercaldo</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>A. Santone</surname>
          </string-name>
          ,
          <article-title>Energy consumption metrics for mobile device dynamic malware detection</article-title>
          .
          <source>Procedia Computer Science</source>
          .
          <year>2019</year>
          , Vol.
          <volume>159</volume>
          , pp.
          <fpage>1045</fpage>
          -
          <lpage>1052</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>J. H.</given-names>
            <surname>Jimenez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Goseva-Popstojanova</surname>
          </string-name>
          ,
          <article-title>Malware detection using power consumption and network traffic data</article-title>
          .
          <source>In 2019 2nd International Conference on Data Intelligence and Security (ICDIS)</source>
          .
          <source>IEEE</source>
          (
          <year>2019</year>
          )
          <fpage>53</fpage>
          -
          <lpage>59</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Shi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Song</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X. Y.</given-names>
            <surname>Li</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>J. Ye</surname>
          </string-name>
          ,
          <article-title>Energy audition based cyber-physical attack detection system in IoT</article-title>
          .
          <source>In Proceedings of the ACM Turing Celebration Conference-China</source>
          (
          <year>2019</year>
          )
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>H.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Xiao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Mercaldo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Ni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Martinelli</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>A. K. Sangaiah</surname>
          </string-name>
          ,
          <article-title>Classification of ransomware families with machine learning based on N-gram of opcodes</article-title>
          .
          <source>Future Generation Computer Systems</source>
          .
          <year>2019</year>
          , Vol.
          <volume>90</volume>
          , pp.
          <fpage>211</fpage>
          -
          <lpage>221</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>A.</given-names>
            <surname>Azmoodeh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dehghantanha</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>K. K. R. Choo</surname>
          </string-name>
          ,
          <article-title>Robust malware detection for internet of (battlefield) things devices using deep eigenspace learning</article-title>
          .
          <source>IEEE transactions on sustainable computing. 2018</source>
          , Vol.
          <volume>4</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>88</fpage>
          -
          <lpage>95</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>H.</given-names>
            <surname>Darabian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dehghantanha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Hashemi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Homayoun</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>K. K. R. Choo</surname>
          </string-name>
          ,
          <article-title>An opcode‐based technique for polymorphic Internet of Things malware detection</article-title>
          .
          <source>Concurrency and Computation: Practice and Experience. 2020</source>
          , Vol.
          <volume>32</volume>
          (
          <issue>6</issue>
          ),
          <year>e5173</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>H.</given-names>
            <surname>Darabian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dehghantanha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Hashemi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Taheri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Azmoodeh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Homayoun &amp; R. M. Parizi</surname>
          </string-name>
          ,
          <article-title>A multiview learning method for malware threat hunting: windows, IoT and android as case studies</article-title>
          .
          <source>World Wide Web. 2020</source>
          , Vol.
          <volume>23</volume>
          (
          <issue>2</issue>
          ), pp.
          <fpage>1241</fpage>
          -
          <lpage>1260</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>F.</given-names>
            <surname>Manavi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Hamzeh</surname>
          </string-name>
          ,
          <article-title>A new approach for malware detection based on evolutionary algorithm</article-title>
          .
          <source>In Proceedings of the Genetic and Evolutionary Computation Conference Companion</source>
          (
          <year>2019</year>
          )
          <fpage>1619</fpage>
          -
          <lpage>1624</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>C.</given-names>
            <surname>Shu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Dosyn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Lytvyn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Vysotska</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sachenko</surname>
          </string-name>
          &amp; S. Jun,
          <article-title>Building of the predicate recognition system for the NLP ontology learning module</article-title>
          .
          <source>In 2019 10th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS)</source>
          <year>2019</year>
          , Vol.
          <volume>2</volume>
          , pp.
          <fpage>802</fpage>
          -
          <lpage>808</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>R.</given-names>
            <surname>Kochan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Lee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kochan</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>A. Sachenko</surname>
          </string-name>
          ,
          <article-title>Development of a dynamically reprogrammable NCAP [network capable application processor]</article-title>
          .
          <source>In Proceedings of the 21st IEEE Instrumentation and Measurement Technology Conference (IEEE Cat. No. 04CH37510)</source>
          .
          <year>2004</year>
          , Vol.
          <volume>2</volume>
          , pp.
          <fpage>1188</fpage>
          -
          <lpage>1193</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>S.</given-names>
            <surname>Lysenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Bobrovnikova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. T.</given-names>
            <surname>Popov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Kharchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Medzatyi</surname>
          </string-name>
          ,
          <article-title>Spyware detection technique based on reinforcement learning</article-title>
          .
          <source>In CEUR Workshop Proceedings</source>
          .
          <year>2020</year>
          , Vol.
          <volume>2623</volume>
          ,
          <fpage>307</fpage>
          -
          <lpage>316</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>S.</given-names>
            <surname>Lysenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Bobrovnikova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Shchuka</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Savenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Cyberattacks</given-names>
            <surname>Detection</surname>
          </string-name>
          <article-title>Technique Based on Evolutionary Algorithms</article-title>
          .
          <source>In 2020 IEEE 11th International Conference on Dependable Systems</source>
          , Services and
          <string-name>
            <surname>Technologies (DESSERT) IEEE</surname>
          </string-name>
          (
          <year>2020</year>
          )
          <fpage>127</fpage>
          -
          <lpage>132</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>A.</given-names>
            <surname>Drozd</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Kuznietsov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Antoshchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Martynyuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Drozd</surname>
          </string-name>
          &amp;
          <string-name>
            <surname>J. Sulima</surname>
          </string-name>
          ,
          <article-title>Evolution of a Problem of the Hidden Faults in the Digital Components of Safety-Related Systens</article-title>
          . In 2018
          <string-name>
            <given-names>IEEE</given-names>
            <surname>East-West</surname>
          </string-name>
          <string-name>
            <given-names>Design</given-names>
            &amp; Test
            <surname>Symposium (EWDTS) IEEE</surname>
          </string-name>
          (
          <year>2018</year>
          )
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>M.</given-names>
            <surname>Zuzcak</surname>
          </string-name>
          , T. Sochor,
          <article-title>Behavioral analysis of bot activity in infected systems using honeypots</article-title>
          .
          <source>In International Conference on Computer Networks</source>
          . Springer, Cham (
          <year>2017</year>
          )
          <fpage>118</fpage>
          -
          <lpage>133</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <given-names>T.</given-names>
            <surname>Sochor</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          <article-title>Zuzcak, High-interaction linux honeypot architecture in recent perspective</article-title>
          .
          <source>In International Conference on Computer Networks</source>
          . Springer, Cham (
          <year>2016</year>
          )
          <fpage>118</fpage>
          -
          <lpage>131</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [35]
          <string-name>
            <given-names>O.</given-names>
            <surname>Barmak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Krak</surname>
          </string-name>
          , E. Manziuk,
          <article-title>Diversity as The Basis for Effective Clustering-Based Classification</article-title>
          .
          <source>ICST</source>
          <year>2020</year>
          (
          <year>2020</year>
          )
          <fpage>53</fpage>
          -
          <lpage>67</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [36]
          <string-name>
            <given-names>A.</given-names>
            <surname>Melnyk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Melnyk</surname>
          </string-name>
          ,
          <article-title>Remote Synthesis of Computer Devices for FPGA-Based IoT Nodes</article-title>
          .
          <year>2020</year>
          10th International Conference on Advanced Computer Information Technologies,
          <source>ACIT 2020 - Proceedings</source>
          <volume>9208882</volume>
          (
          <year>2020</year>
          )
          <fpage>254</fpage>
          -
          <lpage>259</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [37]
          <string-name>
            <given-names>A.</given-names>
            <surname>Melnyk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Melnyk</surname>
          </string-name>
          ,
          <article-title>Specialized Processors Automatic Design Tools-the Basis of SelfConfigurable Computer</article-title>
          and
          <string-name>
            <surname>Cyber-Physical Systems</surname>
          </string-name>
          . 2019 IEEE International Conference on
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>