Abstract
The steady rise of consumer Internet-of-Things (IoT) device usage has proportionally led to an increase in malware targeting embedded systems. Exact hash matching using MD5 or SHA-256 for malware detection is ineffective when small changes alter file hashes. In this paper, we present a lightweight approach based on similarity hashing for detecting Extensible and Linkable Format (ELF) IoT malware binaries. Eighteen datasets, each containing 1,284 malicious and 1,291 clean ELF samples, were collected for analysis. For every sample, three similarity hashes namely SSDEEP, Trend Micro Locality Sensitive Hash (TLSH), and Lempel-Ziv Jaccard Distance (LZJD) were computed under two hashing views. A static-feature view hashes extracted metadata and printable strings, while a file-structure view removes ELF headers and hashes only the executable payload. Using fixed thresholds, the approach avoids machine learning pipelines entirely. On a held-out validation set, SSDEEP (static view) achieved the best overall performance with an accuracy of 78.3% and precision of 0.84, while LZJD (payload view) maintained the highest precision of 0.93 across thresholds, demonstrating its strength in detecting content-level similarities among ELF malware samples. In terms of resource usage, memory profiling revealed that SSDEEP required around 2.4 KB per hash comparison, whereas TLSH and LZJD consumed approximately 0.27 KB on average, confirming the efficiency of their fixed-length hash representations. The proposed pipeline is computationally lightweight as it relies on single-pass hashing, compact hash comparisons, and minimal memory overhead, making it suitable for real-time malware detection in IoT gateways and edge devices.
| Original language | English |
|---|---|
| Title of host publication | 2026 IEEE International Conference on Consumer Electronics, ICCE 2026 |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| ISBN (Electronic) | 9798331553432 |
| DOIs | |
| State | Published - 2026 |
| Event | 2026 IEEE International Conference on Consumer Electronics, ICCE 2026 - Dubai, United Arab Emirates Duration: 3 Feb 2026 → 5 Feb 2026 |
Publication series
| Name | Digest of Technical Papers - IEEE International Conference on Consumer Electronics |
|---|---|
| ISSN (Print) | 0747-668X |
| ISSN (Electronic) | 2159-1423 |
Conference
| Conference | 2026 IEEE International Conference on Consumer Electronics, ICCE 2026 |
|---|---|
| Country/Territory | United Arab Emirates |
| City | Dubai |
| Period | 3/02/26 → 5/02/26 |
Bibliographical note
Publisher Copyright:© 2026 IEEE.
Keywords
- Distance-Based Detection
- Fuzzy Hashing
- IoT Security
- Similarity Hashing
- Static Analysis
ASJC Scopus subject areas
- Industrial and Manufacturing Engineering
- Electrical and Electronic Engineering
Fingerprint
Dive into the research topics of 'No ML, Just Hashes: Code Similarity Distance for Detecting IoT Malware'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver