The Experts below are selected from a list of 10632 Experts worldwide ranked by ideXlab platform

Wagner Meira - One of the best experts on this subject based on the ideXlab platform.

  • The Evolution of Bashlite and Mirai IoT Botnets
    2018 IEEE Symposium on Computers and Communications (ISCC), 2018
    Co-Authors: Artur Marzano, David Alexander, Osvaldo Fonseca, Elverton Fazzion, Cristine Hoepers, Klaus Steding-jessen, Marcelo H. P. C. Chaves, Italo Cunha, Dorgival Guedes, Wagner Meira
    Abstract:

    Vulnerable IoT devices are powerful platforms for building Botnets that cause billion-dollar losses every year. In this work, we study Bashlite Botnets and their successors, Mirai Botnets. In particular, we focus on the evolution of the malware as well as changes in botnet operator behavior. We use monitoring logs from 47 honeypots collected over 11 months. Our results shed new light on those Botnets, and complement previous findings by providing evidence that malware, botnet operators, and malicious activity are becoming more sophisticated. Compared to its predecessor, we find Mirai uses more resilient hosting and control infrastructures, and supports more effective attacks.

  • ISCC - The Evolution of Bashlite and Mirai IoT Botnets
    2018 IEEE Symposium on Computers and Communications (ISCC), 2018
    Co-Authors: Artur Marzano, David Alexander, Osvaldo Fonseca, Elverton Fazzion, Cristine Hoepers, Klaus Steding-jessen, Marcelo H. P. C. Chaves, Italo Cunha, Dorgival Guedes, Wagner Meira
    Abstract:

    Vulnerable IoT devices are powerful platforms for building Botnets that cause billion-dollar losses every year. In this work, we study Bashlite Botnets and their successors, Mirai Botnets. In particular, we focus on the evolution of the malware as well as changes in botnet operator behavior. We use monitoring logs from 47 honeypots collected over 11 months. Our results shed new light on those Botnets, and complement previous findings by providing evidence that malware, botnet operators, and malicious activity are becoming more sophisticated. Compared to its predecessor, we find Mirai uses more resilient hosting and control infrastructures, and supports more effective attacks.

Ivan Osipkov - One of the best experts on this subject based on the ideXlab platform.

  • SIGCOMM - Spamming Botnets: signatures and characteristics
    Proceedings of the ACM SIGCOMM 2008 conference on Data communication - SIGCOMM '08, 2008
    Co-Authors: Yinglian Xie, Kannan Achan, Rina Panigrahy, Geoff Hulten, Ivan Osipkov
    Abstract:

    In this paper, we focus on characterizing spamming Botnets by leveraging both spam payload and spam server traffic properties. Towards this goal, we developed a spam signature generation framework called AutoRE to detect botnet-based spam emails and botnet membership. AutoRE does not require pre-classified training data or white lists. Moreover, it outputs high quality regular expression signatures that can detect botnet spam with a low false positive rate. Using a three-month sample of emails from Hotmail, AutoRE successfully identified 7,721 botnet-based spam campaigns together with 340,050 unique botnet host IP addresses. Our in-depth analysis of the identified Botnets revealed several interesting findings regarding the degree of email obfuscation, properties of botnet IP addresses, sending patterns, and their correlation with network scanning traffic. We believe these observations are useful information in the design of botnet detection schemes.

  • spamming Botnets signatures and characteristics
    ACM Special Interest Group on Data Communication, 2008
    Co-Authors: Yinglian Xie, Kannan Achan, Rina Panigrahy, Geoff Hulten, Ivan Osipkov
    Abstract:

    In this paper, we focus on characterizing spamming Botnets by leveraging both spam payload and spam server traffic properties. Towards this goal, we developed a spam signature generation framework called AutoRE to detect botnet-based spam emails and botnet membership. AutoRE does not require pre-classified training data or white lists. Moreover, it outputs high quality regular expression signatures that can detect botnet spam with a low false positive rate. Using a three-month sample of emails from Hotmail, AutoRE successfully identified 7,721 botnet-based spam campaigns together with 340,050 unique botnet host IP addresses. Our in-depth analysis of the identified Botnets revealed several interesting findings regarding the degree of email obfuscation, properties of botnet IP addresses, sending patterns, and their correlation with network scanning traffic. We believe these observations are useful information in the design of botnet detection schemes.

Yipeng Wang - One of the best experts on this subject based on the ideXlab platform.

  • Modeling Social Engineering Botnet Dynamics across Multiple Social Networks
    2012
    Co-Authors: Shuhao Li, Yongzheng Zhang, Yipeng Wang
    Abstract:

    In recent years, widely spreading Botnets in social networks are becoming a major security threat to both social networking services and the privacy of their users. In order to have a better understanding of the dynamics of these Botnets, defenders should model the process of their propagation. However, previous studies on botnet propagation model have tended to focus solely on characterizing the vulnerability propagation on one infection domain, and left two key properties (cross-domain mobility and user dynamics) untouched. In this paper, we formalize a new propagation model to reveal the general infection process of social engineering Botnets in multiple social networks. This proposed model is based on stochastic process, and investigates two important factors involved in botnet propagation: (i)bot spreading across multiple domains, and (ii)user behaviors in social networks. Furthermore, with statistical data obtained from four real-world social networks, a botnet simulation platform is built based on OMNeT++ to test the validity of our model. The experimental results indicate that our model can accurately predict the infection process of these new advanced Botnets with less than 5% deviation.

  • SEC - Modeling Social Engineering Botnet Dynamics across Multiple Social Networks
    IFIP Advances in Information and Communication Technology, 2012
    Co-Authors: Shuhao Li, Yongzheng Zhang, Yipeng Wang
    Abstract:

    In recent years, widely spreading Botnets in social networks are becoming a major security threat to both social networking services and the privacy of their users. In order to have a better understanding of the dynamics of these Botnets, defenders should model the process of their propagation. However, previous studies on botnet propagation model have tended to focus solely on characterizing the vulnerability propagation on one infection domain, and left two key properties (cross-domain mobility and user dynamics) untouched. In this paper, we formalize a new propagation model to reveal the general infection process of social engineering Botnets in multiple social networks. This proposed model is based on stochastic process, and investigates two important factors involved in botnet propagation: (i)bot spreading across multiple domains, and (ii)user behaviors in social networks. Furthermore, with statistical data obtained from four real-world social networks, a botnet simulation platform is built based on OMNeT++ to test the validity of our model. The experimental results indicate that our model can accurately predict the infection process of these new advanced Botnets with less than 5% deviation.

Christian Rossow - One of the best experts on this subject based on the ideXlab platform.

  • reliable recon in adversarial peer to peer Botnets
    Internet Measurement Conference, 2015
    Co-Authors: Dennis Andriesse, Christian Rossow, Herbert Bos
    Abstract:

    The decentralized nature of Peer-to-Peer (P2P) Botnets precludes traditional takedown strategies, which target dedicated command infrastructure. P2P Botnets replace this infrastructure with command channels distributed across the full infected population. Thus, mitigation strongly relies on accurate reconnaissance techniques which map the botnet population. While prior work has studied passive disturbances to reconnaissance accuracy ---such as IP churn and NAT gateways---, the same is not true of active anti-reconnaissance attacks. This work shows that active attacks against crawlers and sensors occur frequently in major P2P Botnets. Moreover, we show that current crawlers and sensors in the Sality and Zeus Botnets produce easily detectable anomalies, making them prone to such attacks. Based on our findings, we categorize and evaluate vectors for stealthier and more reliable P2P botnet reconnaissance.

  • on advanced monitoring in resilient and unstructured p2p Botnets
    International Conference on Communications, 2014
    Co-Authors: Shankar Karuppayah, Christian Rossow, Mathias Fischer, Max Mühlhäuser
    Abstract:

    Botnets are a serious threat to Internet-based services and end users. The recent paradigm shift from centralized to more sophisticated Peer-to-Peer (P2P)-based Botnets introduces new challenges for security researchers. Centralized Botnets can be easily monitored, and once their command and control server is identified, easily be taken down. However, P2P-based Botnets are much more resilient against such attempts. To make it worse, Botnets like P2P Zeus include additional countermeasures to make monitoring and crawling more difficult for the defenders. In this paper, we discuss in detail the problems of P2P botnet monitoring. As our main contribution, we introduce the Less Invasive Crawling Algorithm (LICA) for efficiently crawling unstructured P2P Botnets and utilize only local information. We compare the performance of LICA with other known crawling methods such as Depth-first and Breadth- first search. This is achieved by simulating these methods on not only a real-world botnet dataset, but also on an unstructured P2P file sharing network dataset. Our analysis results indicate that LICA significantly outperforms the other known crawling methods.

  • IEEE Symposium on Security and Privacy - SoK: P2PWNED - Modeling and Evaluating the Resilience of Peer-to-Peer Botnets
    2013 IEEE Symposium on Security and Privacy, 2013
    Co-Authors: Christian Rossow, Dennis Andriesse, T. Werner, Brett Stone-gross, Daniel Plohmann, Christian Dietrich
    Abstract:

    Centralized Botnets are easy targets for takedown efforts by computer security researchers and law enforcement. Thus, botnet controllers have sought new ways to harden the infrastructures of their Botnets. In order to meet this objective, some botnet operators have (re)designed their Botnets to use Peer-to-Peer (P2P) infrastructures. Many P2P Botnets are far more resilient to takedown attempts than centralized Botnets, because they have no single points of failure. However, P2P Botnets are subject to unique classes of attacks, such as node enumeration and poisoning. In this paper, we introduce a formal graph model to capture the intrinsic properties and fundamental vulnerabilities of P2P Botnets. We apply our model to current P2P Botnets to assess their resilience against attacks. We provide assessments on the sizes of all eleven active P2P Botnets, showing that some P2P botnet families contain over a million bots. In addition, we have prototyped several mitigation strategies to measure the resilience of existing P2P Botnets. We believe that the results from our analysis can be used to assist security researchers in evaluating mitigation strategies against current and future P2P Botnets.

  • sok p2pwned modeling and evaluating the resilience of peer to peer Botnets
    IEEE Symposium on Security and Privacy, 2013
    Co-Authors: Christian Rossow, Dennis Andriesse, T. Werner, Daniel Plohmann, Brett Stonegross, Christian J Dietrich, Herbert Bos
    Abstract:

    Centralized Botnets are easy targets for takedown efforts by computer security researchers and law enforcement. Thus, botnet controllers have sought new ways to harden the infrastructures of their Botnets. In order to meet this objective, some botnet operators have (re)designed their Botnets to use Peer-to-Peer (P2P) infrastructures. Many P2P Botnets are far more resilient to takedown attempts than centralized Botnets, because they have no single points of failure. However, P2P Botnets are subject to unique classes of attacks, such as node enumeration and poisoning. In this paper, we introduce a formal graph model to capture the intrinsic properties and fundamental vulnerabilities of P2P Botnets. We apply our model to current P2P Botnets to assess their resilience against attacks. We provide assessments on the sizes of all eleven active P2P Botnets, showing that some P2P botnet families contain over a million bots. In addition, we have prototyped several mitigation strategies to measure the resilience of existing P2P Botnets. We believe that the results from our analysis can be used to assist security researchers in evaluating mitigation strategies against current and future P2P Botnets.

Herbert Bos - One of the best experts on this subject based on the ideXlab platform.

  • reliable recon in adversarial peer to peer Botnets
    Internet Measurement Conference, 2015
    Co-Authors: Dennis Andriesse, Christian Rossow, Herbert Bos
    Abstract:

    The decentralized nature of Peer-to-Peer (P2P) Botnets precludes traditional takedown strategies, which target dedicated command infrastructure. P2P Botnets replace this infrastructure with command channels distributed across the full infected population. Thus, mitigation strongly relies on accurate reconnaissance techniques which map the botnet population. While prior work has studied passive disturbances to reconnaissance accuracy ---such as IP churn and NAT gateways---, the same is not true of active anti-reconnaissance attacks. This work shows that active attacks against crawlers and sensors occur frequently in major P2P Botnets. Moreover, we show that current crawlers and sensors in the Sality and Zeus Botnets produce easily detectable anomalies, making them prone to such attacks. Based on our findings, we categorize and evaluate vectors for stealthier and more reliable P2P botnet reconnaissance.

  • sok p2pwned modeling and evaluating the resilience of peer to peer Botnets
    IEEE Symposium on Security and Privacy, 2013
    Co-Authors: Christian Rossow, Dennis Andriesse, T. Werner, Daniel Plohmann, Brett Stonegross, Christian J Dietrich, Herbert Bos
    Abstract:

    Centralized Botnets are easy targets for takedown efforts by computer security researchers and law enforcement. Thus, botnet controllers have sought new ways to harden the infrastructures of their Botnets. In order to meet this objective, some botnet operators have (re)designed their Botnets to use Peer-to-Peer (P2P) infrastructures. Many P2P Botnets are far more resilient to takedown attempts than centralized Botnets, because they have no single points of failure. However, P2P Botnets are subject to unique classes of attacks, such as node enumeration and poisoning. In this paper, we introduce a formal graph model to capture the intrinsic properties and fundamental vulnerabilities of P2P Botnets. We apply our model to current P2P Botnets to assess their resilience against attacks. We provide assessments on the sizes of all eleven active P2P Botnets, showing that some P2P botnet families contain over a million bots. In addition, we have prototyped several mitigation strategies to measure the resilience of existing P2P Botnets. We believe that the results from our analysis can be used to assist security researchers in evaluating mitigation strategies against current and future P2P Botnets.