{"id":"https://openalex.org/W7141138068","doi":"https://doi.org/10.1109/icce67443.2026.11449826","title":"Two-View Honeypot Framework for Behavioral Analysis of Consumer IoT Attack Campaigns","display_name":"Two-View Honeypot Framework for Behavioral Analysis of Consumer IoT Attack Campaigns","publication_year":2026,"publication_date":"2026-02-03","ids":{"openalex":"https://openalex.org/W7141138068","doi":"https://doi.org/10.1109/icce67443.2026.11449826"},"language":null,"primary_location":{"id":"doi:10.1109/icce67443.2026.11449826","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icce67443.2026.11449826","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 IEEE International Conference on Consumer Electronics (ICCE)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5053439651","display_name":"Sara Afzal","orcid":"https://orcid.org/0009-0001-6617-5263"},"institutions":[{"id":"https://openalex.org/I4210130157","display_name":"Institute of Informatics and Telematics","ror":"https://ror.org/02gdcn153","country_code":"IT","type":"facility","lineage":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Sara Afzal","raw_affiliation_strings":["National Research Council (CNR),Institute of Informatics and Telematics (IIT),Pisa,Italy"],"affiliations":[{"raw_affiliation_string":"National Research Council (CNR),Institute of Informatics and Telematics (IIT),Pisa,Italy","institution_ids":["https://openalex.org/I4210130157"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5018881921","display_name":"Farrukh Aslam Khan","orcid":"https://orcid.org/0000-0002-7023-7172"},"institutions":[{"id":"https://openalex.org/I28022161","display_name":"King Saud University","ror":"https://ror.org/02f81g417","country_code":"SA","type":"education","lineage":["https://openalex.org/I28022161"]}],"countries":["SA"],"is_corresponding":false,"raw_author_name":"Farrukh Aslam Khan","raw_affiliation_strings":["King Saud University,Center of Excellence in Information Assurance (CoEIA),Riyadh,Saudi Arabia"],"affiliations":[{"raw_affiliation_string":"King Saud University,Center of Excellence in Information Assurance (CoEIA),Riyadh,Saudi Arabia","institution_ids":["https://openalex.org/I28022161"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5042418294","display_name":"Abraham Gebrehiwot","orcid":null},"institutions":[{"id":"https://openalex.org/I4210130157","display_name":"Institute of Informatics and Telematics","ror":"https://ror.org/02gdcn153","country_code":"IT","type":"facility","lineage":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Abraham Gebrehiwot","raw_affiliation_strings":["National Research Council (CNR),Institute of Informatics and Telematics (IIT),Pisa,Italy"],"affiliations":[{"raw_affiliation_string":"National Research Council (CNR),Institute of Informatics and Telematics (IIT),Pisa,Italy","institution_ids":["https://openalex.org/I4210130157"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5127001927","display_name":"Filippo Maria Lauria","orcid":null},"institutions":[{"id":"https://openalex.org/I4210130157","display_name":"Institute of Informatics and Telematics","ror":"https://ror.org/02gdcn153","country_code":"IT","type":"facility","lineage":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Filippo Maria Lauria","raw_affiliation_strings":["National Research Council (CNR),Institute of Informatics and Telematics (IIT),Pisa,Italy"],"affiliations":[{"raw_affiliation_string":"National Research Council (CNR),Institute of Informatics and Telematics (IIT),Pisa,Italy","institution_ids":["https://openalex.org/I4210130157"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5053439651"],"corresponding_institution_ids":["https://openalex.org/I4210130157"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.92261579,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.09790000319480896,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.09790000319480896,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.060100000351667404,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.05139999836683273,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/behavioral-analysis","display_name":"Behavioral analysis","score":0.7157999873161316},{"id":"https://openalex.org/keywords/honeypot","display_name":"Honeypot","score":0.6234999895095825},{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.5095000267028809},{"id":"https://openalex.org/keywords/pattern-analysis","display_name":"Pattern analysis","score":0.34150001406669617},{"id":"https://openalex.org/keywords/behavioral-pattern","display_name":"Behavioral pattern","score":0.3188999891281128},{"id":"https://openalex.org/keywords/qualitative-analysis","display_name":"Qualitative analysis","score":0.313400000333786}],"concepts":[{"id":"https://openalex.org/C2989277270","wikidata":"https://www.wikidata.org/wiki/Q168338","display_name":"Behavioral analysis","level":2,"score":0.7157999873161316},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6327000260353088},{"id":"https://openalex.org/C191267431","wikidata":"https://www.wikidata.org/wiki/Q911932","display_name":"Honeypot","level":2,"score":0.6234999895095825},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5450000166893005},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.5095000267028809},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.3799999952316284},{"id":"https://openalex.org/C2985264313","wikidata":"https://www.wikidata.org/wiki/Q378859","display_name":"Pattern analysis","level":2,"score":0.34150001406669617},{"id":"https://openalex.org/C83804111","wikidata":"https://www.wikidata.org/wiki/Q1063558","display_name":"Behavioral pattern","level":2,"score":0.3188999891281128},{"id":"https://openalex.org/C3018587665","wikidata":"https://www.wikidata.org/wiki/Q7268696","display_name":"Qualitative analysis","level":3,"score":0.313400000333786},{"id":"https://openalex.org/C38369872","wikidata":"https://www.wikidata.org/wiki/Q7445009","display_name":"Security analysis","level":2,"score":0.30160000920295715},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2777000069618225},{"id":"https://openalex.org/C2781317605","wikidata":"https://www.wikidata.org/wiki/Q7832483","display_name":"Traffic analysis","level":2,"score":0.2630000114440918},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.25279998779296875},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.2524999976158142}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icce67443.2026.11449826","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icce67443.2026.11449826","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 IEEE International Conference on Consumer Electronics (ICCE)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":14,"referenced_works":["https://openalex.org/W2057036604","https://openalex.org/W2897249806","https://openalex.org/W2915626801","https://openalex.org/W3098605233","https://openalex.org/W3135306750","https://openalex.org/W3152342827","https://openalex.org/W3158792679","https://openalex.org/W4287848949","https://openalex.org/W4311165999","https://openalex.org/W4384202327","https://openalex.org/W4385948714","https://openalex.org/W4401107035","https://openalex.org/W4402215618","https://openalex.org/W4407106963"],"related_works":[],"abstract_inverted_index":{"Internet-facing":[0],"consumer":[1],"Internet":[2],"of":[3,51],"Things":[4],"(IoT)":[5],"devices":[6],"are":[7],"probed":[8],"and":[9,25,86,102,105,145,157,160,171,180,219,238],"compromised":[10],"at":[11,202],"scale,":[12],"yet":[13],"converting":[14],"raw":[15,250],"honeypot":[16,252],"logs":[17,54,253],"into":[18],"clear":[19,103],"evidence":[20],"about":[21],"how":[22],"attacks":[23],"operate":[24],"which":[26],"sessions":[27,124],"belong":[28],"to":[29,48,80,254],"the":[30,66,88,106,135,216,243],"same":[31,217],"campaign":[32],"remains":[33],"difficult,":[34],"especially":[35],"without":[36,257],"labels.":[37],"In":[38,65,134],"this":[39],"work,":[40],"we":[41,69,98,138],"present":[42],"a":[43,94,116,149,196,226,246],"scalable":[44],"two-view":[45],"pipeline":[46,244],"applied":[47],"one":[49],"year":[50],"Cowrie":[52],"SSH/Telnet":[53],"that":[55,187],"emulate":[56],"vulnerable":[57],"IoT":[58,189,251],"endpoints":[59],"(1.77M":[60],"sessions;":[61],"3.67M":[62],"command":[63,73,236],"events).":[64],"behavior":[67],"view,":[68,137],"encode":[70],"each":[71],"session\u2019s":[72],"sequence":[74],"with":[75,90,129,154,163],"an":[76],"E5":[77],"encoder,":[78],"reduce":[79],"50":[81],"dimensions":[82],"via":[83],"Incremental":[84],"PCA,":[85],"cluster":[87],"corpus":[89],"MiniBatchKMeans":[91],"(k=250).":[92],"On":[93],"97k":[95],"stratified":[96],"sample,":[97],"observe":[99],"high":[100],"Silhouette":[101],"exemplars,":[104],"full":[107],"run":[108],"completes":[109],"in":[110],"minutes":[111],"on":[112,120],"research":[113],"hardware.":[114],"As":[115],"robustness":[117],"check,":[118],"HDBSCAN":[119],"~4\u00d710<sup":[121],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[122],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">5</sup>":[123],"discovers":[125],"44":[126],"dense":[127],"groups":[128],"13.94%":[130],"labeled":[131],"as":[132,225],"noise.":[133],"infrastructure":[136],"independently":[139],"extract":[140],"normalized":[141],"URLs,":[142],"domains,":[143],"IPv4s,":[144],"SHA-256":[146],"hashes,":[147],"build":[148],"14-day":[150],"time-windowed":[151],"artifact-sharing":[152],"graph":[153,167],"type-weighted":[155],"edges":[156],"degree":[158],"caps,":[159],"detect":[161],"communities":[162,186],"Louvain.":[164],"A":[165],"representative":[166],"has":[168,177],"250,043":[169],"nodes":[170,179],"1,575,383":[172],"edges;":[173],"its":[174],"giant":[175],"component":[176],"18,938":[178],"102,289":[181],"edges,":[182],"revealing":[183],"distinct,":[184],"bursty":[185],"target":[188],"devices.":[190],"Comparing":[191],"views":[192],"for":[193],"overlap":[194],"yields":[195],"low":[197],"Adjusted":[198],"Rand":[199],"Index":[200],"(0.019":[201],"\u2248":[203],"1.07%":[204],"coverage),":[205],"indicating":[206],"they":[207],"capture":[208],"complementary":[209],"structure;":[210],"similar":[211],"workflows":[212],"need":[213],"not":[214],"reuse":[215],"infrastructure,":[218],"vice":[220],"versa.":[221],"We":[222],"package":[223],"outputs":[224],"compact":[227],"\"findings":[228],"pack\"":[229],"per":[230],"large":[231],"community":[232],"(top":[233],"artifacts,":[234],"exemplar":[235],"snippets,":[237],"weekly":[239],"activity":[240],"curves).":[241],"Overall,":[242],"offers":[245],"practical":[247],"path":[248],"from":[249],"campaign-level":[255],"insight":[256],"supervision.":[258]},"counts_by_year":[],"updated_date":"2026-03-29T06:01:01.467347","created_date":"2026-03-28T00:00:00"}
