Skip to main navigation Skip to search Skip to main content

No ML, Just Hashes: Code Similarity Distance for Detecting IoT Malware

  • Mohammed Rauf Ali Khan*
  • , Louai Al-Awami
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The steady rise of consumer Internet-of-Things (IoT) device usage has proportionally led to an increase in malware targeting embedded systems. Exact hash matching using MD5 or SHA-256 for malware detection is ineffective when small changes alter file hashes. In this paper, we present a lightweight approach based on similarity hashing for detecting Extensible and Linkable Format (ELF) IoT malware binaries. Eighteen datasets, each containing 1,284 malicious and 1,291 clean ELF samples, were collected for analysis. For every sample, three similarity hashes namely SSDEEP, Trend Micro Locality Sensitive Hash (TLSH), and Lempel-Ziv Jaccard Distance (LZJD) were computed under two hashing views. A static-feature view hashes extracted metadata and printable strings, while a file-structure view removes ELF headers and hashes only the executable payload. Using fixed thresholds, the approach avoids machine learning pipelines entirely. On a held-out validation set, SSDEEP (static view) achieved the best overall performance with an accuracy of 78.3% and precision of 0.84, while LZJD (payload view) maintained the highest precision of 0.93 across thresholds, demonstrating its strength in detecting content-level similarities among ELF malware samples. In terms of resource usage, memory profiling revealed that SSDEEP required around 2.4 KB per hash comparison, whereas TLSH and LZJD consumed approximately 0.27 KB on average, confirming the efficiency of their fixed-length hash representations. The proposed pipeline is computationally lightweight as it relies on single-pass hashing, compact hash comparisons, and minimal memory overhead, making it suitable for real-time malware detection in IoT gateways and edge devices.

Original languageEnglish
Title of host publication2026 IEEE International Conference on Consumer Electronics, ICCE 2026
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331553432
DOIs
StatePublished - 2026
Event2026 IEEE International Conference on Consumer Electronics, ICCE 2026 - Dubai, United Arab Emirates
Duration: 3 Feb 20265 Feb 2026

Publication series

NameDigest of Technical Papers - IEEE International Conference on Consumer Electronics
ISSN (Print)0747-668X
ISSN (Electronic)2159-1423

Conference

Conference2026 IEEE International Conference on Consumer Electronics, ICCE 2026
Country/TerritoryUnited Arab Emirates
CityDubai
Period3/02/265/02/26

Bibliographical note

Publisher Copyright:
© 2026 IEEE.

Keywords

  • Distance-Based Detection
  • Fuzzy Hashing
  • IoT Security
  • Similarity Hashing
  • Static Analysis

ASJC Scopus subject areas

  • Industrial and Manufacturing Engineering
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'No ML, Just Hashes: Code Similarity Distance for Detecting IoT Malware'. Together they form a unique fingerprint.

Cite this