ご案内 入会して研究会活動をもっとお得に!研究会参加費・年間登録費が会員価格になります。
お知らせ 【重要】研究会参加費の支払いおよび原稿アップロード手続きの変更に関するご案内
電子情報通信学会 研究会発表申込システム
講演論文 詳細
技報閲覧サービス
[ログイン]
技報アーカイブ
 トップに戻る 前のページに戻る   [Japanese] / [English] 

講演抄録/キーワード
講演名 2026-03-04 10:10
Understanding Web-Exposed Cybercrime-Related Content on IoT Botnet Infrastructure
Qingxin MaoYin Minn Pa PaRui TanabeKatsunari YoshiokaYNUICSS2025-117
抄録 (和) (まだ登録されていません) 
(英) In recent years, IoT botnets conducting cyberattacks such as DDoS attacks have become a significant threat, making it important to understand their operational realities. Prior work has characterized IoT botnet ecosystems by analyzing their growth and evolution, measuring properties of Command and Control (C2) and download-server infrastructure (e.g., lifetime and hosting environments). While these works show interesting findings on the IoT botnet, primarily works focused on the attacks and the devices involved, without addressing the relationship between the attacks and the attackers themselves. Therefore, it remains unclear if the attackers are utilizing their infrastructure for other cybercriminal activities beyond executing attacks. Our prior study investigated web-exposed content on IoT botnet infrastructure but focused only on the DDoS-for-hire cases. In this study, we broaden the scope to cover multiple cybercrime types and measure what other cybercrime activities are hosted on IoT botnet infrastructure. We conduct a one-year longitudinal crawling campaign of webpages exposed on IoT botnet infrastructure (Aug. 2024–Aug. 2025), collecting 43,406 rendered webpage screenshots from the infrastructure IPs and their associated domains. Using an LLM-based visual classifier, we identify 1,509 screenshots related to cybercrime, which corresponds to 3.48% of the raw dataset, suggesting that such cybercrime-related reuse of IoT botnet infrastructure is not pervasive in our observation. We then manually group screenshots with identical webpage content into cases and remove cases with low relevance to attacker-controlled infrastructure, resulting in 32 final cases of infrastructure reuse. These cases span all five cybercrime offence types (Types A–E), showing that the web-exposed content observed on IoT botnet infrastructure is not limited to a single category of cybercrime activity. Finally, our case-level analysis reveals that some cases appear across multiple infrastructure roles; this indicates that certain infrastructure IPs are used in multiple botnet-infrastructure roles (e.g., simultaneously appearing as C2/download/loader endpoints) while also exposing web content corresponding to other types of cybercrime activities.
キーワード (和) / / / / / / /  
(英) CaaS / IoT Botnet Infrastructure / Passive DNS / LLM / / / /  
文献情報 信学技報, vol. 125, no. 381, ICSS2025-117, pp. 231-238, 2026年3月.
資料番号 ICSS2025-117 
発行日 2026-02-24 (ICSS) 
ISSN Online edition: ISSN 2432-6380
著作権に
ついて
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034)
PDFダウンロード ICSS2025-117

研究会情報
研究会 ICSS IPSJ-SPT  
開催期間 2026-03-03 - 2026-03-04 
開催地(和) 沖縄県立美術館・博物館 
開催地(英) Okinawa Prefectural Museum & Art Museum 
テーマ(和) セキュリティ,トラスト,一般 
テーマ(英) Security, Trust, etc. 
講演論文情報の詳細
申込み研究会 ICSS 
会議コード 2026-03-ICSS-SPT 
本文の言語 英語 
タイトル(和)  
サブタイトル(和)  
タイトル(英) Understanding Web-Exposed Cybercrime-Related Content on IoT Botnet Infrastructure 
サブタイトル(英)  
キーワード(1)(和/英) / CaaS  
キーワード(2)(和/英) / IoT Botnet Infrastructure  
キーワード(3)(和/英) / Passive DNS  
キーワード(4)(和/英) / LLM  
キーワード(5)(和/英) /  
キーワード(6)(和/英) /  
キーワード(7)(和/英) /  
キーワード(8)(和/英) /  
第1著者 氏名(和/英/ヨミ) 毛 清昕 / Qingxin Mao / モウ セイキン
第1著者 所属(和/英) 横浜国立大学 (略称: 横浜国大)
Yokohama National University (略称: YNU)
第2著者 氏名(和/英/ヨミ) インミン パパ / Yin Minn Pa Pa / インミン パパ
第2著者 所属(和/英) 横浜国立大学 (略称: 横浜国大)
Yokohama National University (略称: YNU)
第3著者 氏名(和/英/ヨミ) 田辺 瑠偉 / Rui Tanabe / タナベ ルイ
第3著者 所属(和/英) 横浜国立大学 (略称: 横浜国大)
Yokohama National University (略称: YNU)
第4著者 氏名(和/英/ヨミ) 吉岡 克成 / Katsunari Yoshioka / ヨシオカ カツナリ
第4著者 所属(和/英) 横浜国立大学 (略称: 横浜国大)
Yokohama National University (略称: YNU)
第5著者 氏名(和/英/ヨミ) / /
第5著者 所属(和/英) (略称: )
(略称: )
第6著者 氏名(和/英/ヨミ) / /
第6著者 所属(和/英) (略称: )
(略称: )
第7著者 氏名(和/英/ヨミ) / /
第7著者 所属(和/英) (略称: )
(略称: )
第8著者 氏名(和/英/ヨミ) / /
第8著者 所属(和/英) (略称: )
(略称: )
第9著者 氏名(和/英/ヨミ) / /
第9著者 所属(和/英) (略称: )
(略称: )
第10著者 氏名(和/英/ヨミ) / /
第10著者 所属(和/英) (略称: )
(略称: )
第11著者 氏名(和/英/ヨミ) / /
第11著者 所属(和/英) (略称: )
(略称: )
第12著者 氏名(和/英/ヨミ) / /
第12著者 所属(和/英) (略称: )
(略称: )
第13著者 氏名(和/英/ヨミ) / /
第13著者 所属(和/英) (略称: )
(略称: )
第14著者 氏名(和/英/ヨミ) / /
第14著者 所属(和/英) (略称: )
(略称: )
第15著者 氏名(和/英/ヨミ) / /
第15著者 所属(和/英) (略称: )
(略称: )
第16著者 氏名(和/英/ヨミ) / /
第16著者 所属(和/英) (略称: )
(略称: )
第17著者 氏名(和/英/ヨミ) / /
第17著者 所属(和/英) (略称: )
(略称: )
第18著者 氏名(和/英/ヨミ) / /
第18著者 所属(和/英) (略称: )
(略称: )
第19著者 氏名(和/英/ヨミ) / /
第19著者 所属(和/英) (略称: )
(略称: )
第20著者 氏名(和/英/ヨミ) / /
第20著者 所属(和/英) (略称: )
(略称: )
第21著者 氏名(和/英/ヨミ) / /
第21著者 所属(和/英) (略称: )
(略称: )
第22著者 氏名(和/英/ヨミ) / /
第22著者 所属(和/英) (略称: )
(略称: )
第23著者 氏名(和/英/ヨミ) / /
第23著者 所属(和/英) (略称: )
(略称: )
第24著者 氏名(和/英/ヨミ) / /
第24著者 所属(和/英) (略称: )
(略称: )
第25著者 氏名(和/英/ヨミ) / /
第25著者 所属(和/英) (略称: )
(略称: )
第26著者 氏名(和/英/ヨミ) / /
第26著者 所属(和/英) (略称: )
(略称: )
第27著者 氏名(和/英/ヨミ) / /
第27著者 所属(和/英) (略称: )
(略称: )
第28著者 氏名(和/英/ヨミ) / /
第28著者 所属(和/英) (略称: )
(略称: )
第29著者 氏名(和/英/ヨミ) / /
第29著者 所属(和/英) (略称: )
(略称: )
第30著者 氏名(和/英/ヨミ) / /
第30著者 所属(和/英) (略称: )
(略称: )
第31著者 氏名(和/英/ヨミ) / /
第31著者 所属(和/英) (略称: )
(略称: )
第32著者 氏名(和/英/ヨミ) / /
第32著者 所属(和/英) (略称: )
(略称: )
第33著者 氏名(和/英/ヨミ) / /
第33著者 所属(和/英) (略称: )
(略称: )
第34著者 氏名(和/英/ヨミ) / /
第34著者 所属(和/英) (略称: )
(略称: )
第35著者 氏名(和/英/ヨミ) / /
第35著者 所属(和/英) (略称: )
(略称: )
第36著者 氏名(和/英/ヨミ) / /
第36著者 所属(和/英) (略称: )
(略称: )
講演者 第1著者 
発表日時 2026-03-04 10:10:00 
発表時間 20分 
申込先研究会 ICSS 
資料番号 ICSS2025-117 
巻番号(vol) vol.125 
号番号(no) no.381 
ページ範囲 pp.231-238 
ページ数
発行日 2026-02-24 (ICSS) 


[研究会発表申込システムのトップページに戻る]

[電子情報通信学会ホームページ]


IEICE / 電子情報通信学会