Ransomware in Resource-Constrained Industrial IoT Networks: There Actually is a Threat

Yuxiang Huang*, Calvin Brierley, Adel ElZemity, James Pope, Jiteng Ma, Antonio Di Buono, Budi Arief, George Oikonomou

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference Contribution (Conference Proceeding)

Abstract

The threat of ransomware attacks against Industrial Internet of Things (IIoT) networks, particularly networks of resource-constrained devices, is starting to become a reality. In this paper, we contend that the threat of ransomware infection of an IIoT environment is not only plausible, but that it also exhibits different properties compared to ransomware attacks against traditional desktop systems, necessitating a new and more appropriate approach to deal with this threat. In particular, we articulate the unique characteristics of ransomware behaviour in IIoT networks considering the distinctive characteristics, such as computationally-constrained devices and low-power wireless communication protocols. Furthermore, we outline the necessary attributes for ransomware to effectively compromise and propagate within IIoT networks. To back our argument, we present a proof-of-concept (PoC) IIoT ransomware prototype. To highlight the generality of our work, we have developed the prototype for two different hardware platforms, powered by two different open source embedded operating systems: Contiki-NG and Zephyr.
Original languageEnglish
Title of host publication 2025 21st International Conference on Distributed Computing in Smart Systems and the Internet of Things (DCOSS-IoT)
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Publication statusAccepted/In press - 30 Apr 2025
Event21st Annual International Conference on Distributed Computing in Smart Systems and the Internet of Things (DCOSS-IoT 2025) - Lucca, Italy
Duration: 9 Jun 202511 Jun 2025
https://dcoss.org/

Publication series

NameInternational Conference on Distributed Computing in Sensor Systems (DCOSS)
PublisherIEEE
ISSN (Print)2325-2936
ISSN (Electronic)2325-2944

Conference

Conference21st Annual International Conference on Distributed Computing in Smart Systems and the Internet of Things (DCOSS-IoT 2025)
Abbreviated titleDCOSS-IOT
Country/TerritoryItaly
CityLucca
Period9/06/2511/06/25
Internet address

Fingerprint

Dive into the research topics of 'Ransomware in Resource-Constrained Industrial IoT Networks: There Actually is a Threat'. Together they form a unique fingerprint.

Cite this