Related Experiment Video
Updated: May 3, 2026

05:30
Large Scale Energy Efficient Sensor Network Routing Using a Quantum Processor Unit
Published on: September 8, 2023
1.3K
In-Memory Shellcode Runner Detection in Internet of Things (IoT) Networks: A Lightweight Behavioral and Semantic
Jean Rosemond Dora1, Ladislav Hluchý1, Michal Staňo1
1Institute of Informatics, Slovak Academy of Sciences (IISAS), 84507 Bratislava, Slovakia.
Sensors (Basel, Switzerland)
|September 13, 2025
Summary
This study introduces a new framework to detect in-memory shellcode runners, a type of malware targeting Internet of Things devices. The multi-layered approach enhances cybersecurity by analyzing memory and system calls for hidden threats.
Area of Science:
- Cybersecurity
- Internet of Things (IoT) Security
- Malware Detection
Background:
- The proliferation of Internet of Things (IoT) devices increases vulnerability to sophisticated cyber threats.
- In-memory shellcode runners pose a significant risk by evading traditional security measures.
- Resource-constrained IoT systems require specialized security solutions.
Purpose of the Study:
- To present a comprehensive framework for detecting in-memory shellcode runners in IoT environments.
- To analyze existing security limitations and challenges in detecting such advanced threats.
- To propose a novel, multi-layered detection approach tailored for IoT networks.
Main Methods:
- Developed a multi-layered detection framework combining entropy-based anomaly scoring and lightweight behavioral monitoring.
- Utilized Graph Neural Network methods for System Call Semantic Graph Analysis.
- Focused on runtime analysis of process memory, system call patterns, and network behavior.
Main Results:
- The proposed framework effectively identifies in-memory attacks by analyzing subtle indicators of compromise.
- Empirical evaluation against simulated and real-world IoT attacks demonstrated the approach's efficiency.
- Identified specific challenges in implementing the detection framework in dynamic environments.
Conclusions:
- The developed framework offers a crucial advancement in securing IoT environments against in-memory shellcode runner attacks.
- Runtime analysis of memory, system calls, and network behavior is vital for detecting fileless malware.
- Further research is needed to address implementation challenges and optimize performance.
Related Concept Videos
Leaky Scanning
5.6K
During most eukaryotic translation processes, the small 40S ribosome subunit scans an mRNA from its 5' end until it encounters the first start AUG codon. The large 60S ribosomal subunit then joins the smaller one to initiate protein synthesis. The location of the translation initiation is largely determined by the nucleotides near the start codon as there may be multiple translation initiation sites present on the mRNA. Marilyn Kozak discovered that the sequence RCCAUGG (where R...
5.6K
Machines
557
Machines are complex structures consisting of movable, pin-connected multi-force members that work together to transmit forces. One example of a machine is the cutting plier, which is used to cut wires by applying forces to its handles. When equal and opposite forces are exerted on the handles of the cutting plier, they cause the cutting edges to come together and apply equal and opposite reaction forces on the wire, which are greater than the applied forces.
A free-body diagram of the...
A free-body diagram of the...
557
Machines: Problem Solving II
648
Machines are complex structures consisting of movable, pin-connected multi-force members that work together to transmit forces. Consider a lifting tong carrying a 100 kg load. It comprises movable sections DAF and CBG linked together with member AB.
648
Types of Errors: Detection and Minimization
10.2K
Error is the deviation of the obtained result from the true, expected value or the estimated central value. Errors are expressed in absolute or relative terms.
Absolute error in a measurement is the numerical difference from the true or central value. Relative error is the ratio between absolute error and the true or central value, expressed as a percentage.
Errors can be classified by source, magnitude, and sign. There are three types of errors: systematic, random, and gross.
Systematic or...
Absolute error in a measurement is the numerical difference from the true or central value. Relative error is the ratio between absolute error and the true or central value, expressed as a percentage.
Errors can be classified by source, magnitude, and sign. There are three types of errors: systematic, random, and gross.
Systematic or...
10.2K
Mass Analyzers: Overview
1.6K
The mass analyzer is a crucial component of the mass spectrometer. In the ionization chamber, the vaporized sample is bombarded with a high-energy electron beam to generate a radical cation and further fragment into neutral molecules, radicals, and cations. A series of negatively charged accelerator plates accelerate the cations into the mass analyzer. The mass analyzer separates ions according to their mass-to-charge (m/z) ratios and then directs them to the detector. The common types of mass...
1.6K
Mass Analyzers: Common Types
1.4K
The quadrupole mass analyzer consists of four cylindrical metal rods arranged in a diamond carrying a DC voltage and a radio-frequency AC voltage. The motion of ions through the quadrupole depends on the field strength, causing only ions of a certain m/z to resonate successfully and strike the detector at a given field strength. Though the transmission rate for these analyzers is high, the exact elemental composition of the sample is not determined because of low resolution; however, they are...
1.4K