The Experts below are selected from a list of 57 Experts worldwide ranked by ideXlab platform

Christian Doerr - One of the best experts on this subject based on the ideXlab platform.

  • CCS - Just the Tip of the Iceberg: Internet-Scale Exploitation of Routers for Cryptojacking
    Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, 2019
    Co-Authors: Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr
    Abstract:

    The release of an efficient browser-based cryptominer, as introduced by Coinhive in 2017, has quickly spread throughout the web either as a new source of revenue for websites or exploited within the context of hacks and malicious advertisements. Several studies have analyzed the Alexa Top 1M and found 380 - 3,200 (0.038% - 0.32%) to be actively mining, with an estimated $41,000 per month revenue for the top 10 perpetrators. While placing a cryptominer on a popular website supplies considerable returns from its visitors' web browsers, it only generates revenue while a client is visiting the page. Even though large popular websites attract millions of visitors, the relatively low number of exploiting websites limits the total revenue that can be made. In this paper, we report on a new attack vector that drastically overshadows all existing cryptojacking activity discovered to date. Through a firmware vulnerability in MikroTik routers, cyber criminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing web connection. Thus, every web page visited by any user behind an infected router would mine to profit the criminals. Based on NetFlows recorded in a Tier 1 Network, semiweekly crawls and telescope traffic, we followed their activities over a period of 10 months, and report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, approximately 70% of all MikroTik devices deployed worldwide. We observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. Our results show that cryptojacking through MITM attacks is highly lucrative, a factor of 30 more than previous attack vectors.

  • USENIX Security Symposium - Inadvertently Making Cyber Criminals Rich: A Comprehensive Study of Cryptojacking Campaigns at Internet Scale
    2019
    Co-Authors: Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr
    Abstract:

    Cryptojacking, a phenomenon also known as drive-by cryptomining, involves stealing computing power from others to be used in illicit cryptomining. While first observed as host-based infections with low activity, the release of an efficient browser-based cryptomining application -- as introduced by Coinhive in 2017 -- has skyrocketed cryptojacking activity in recent years. This novel method of monetizing Web activity attracted both website owners and cybercriminals seeking new methods to profit from. Website owners installed a cryptominer on their domains, while cybercriminals deployed cryptominers in large campaigns spread over numerous domains. Several studies developed detection methods to identify these browser-based cryptominers on websites, but none of these studies focused on the extent and coordination of campaigns deployed by adversaries. Furthermore, the prevalence of cryptojacking on websites is not well estimated yet and the potentially largest attack vector -- a man-in-the-middle attack -- has never been researched before. In this thesis, we perform multiple large studies on cryptojacking to fill these gaps. After crawling a random sample of 49M domains, 20% of the Internet, we conclude that cryptojacking is present on 0.011% of all domains and that adult content is the most prevalent category of websites affected. We show that this percentage is significantly larger in the popular part of the Internet. This led to the conclusion that surveying solely domains listed in the Alexa Top 1M to estimate cryptojacking prevalence results in an overestimation of the problem. Furthermore, we show that infection rates on different Top Level Domains (TLDs) differ widely, as the Russian zone is home to a disproportionate number of cryptojacking domains, while other large TLDs -- such as .com -- show a significantly lower number of infections. In another crawl, we have identified 204 cryptojacking campaigns on websites, an order of magnitude more than previous work, which indicates that the extent of these campaigns is heavily underestimated. The results of the two crawls combined reveal that 48% of all cryptojacking activity on websites is organized. The identified campaigns ranged in sizes from only 5 to 987 websites and we discovered that cybercriminals have chosen third-party software -- such as WordPress and Drupal -- as their method of choice for spreading cryptojacking infections efficiently. With a novel method of using NetFlow data recorded in a Tier 1 Network, we estimated the popularity of mining applications, which showed that while Coinhive has a larger installed base, CoinImp WebSocket proxies were digesting significantly more traffic in the second half of 2018. We have reported about a new attack vector that drastically overshadows all other cryptojacking activity. Through a firmware vulnerability in MikroTik routers, cybercriminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing Web connection. Thus, every Web page visited by any user behind an infected router would mine to profit the adversaries. Based on the aforementioned NetFlow data, weekly third-party crawls and Network telescope traffic, we were able to follow their activities over a period of 10 months. We report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, which is approximately 70% of all MikroTik devices deployed in the world. During the peak of this attack, more than 440K routers were infected concurrently. We have discovered that half of the infected routers are patched within 18 days after compromise, but 30% of the infections last longer than 50 days. Additionally, we observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. The combination of datasets allowed us to link tens of seemingly different infections to one actor. Our analysis of cryptojacking with a focus on organized campaigns has shown that cybercriminals have successfully discovered a new method for monetary gain. With the discontinuation of Coinhive due to decreased Monero prices in March 2019, the cryptojacking landscape has changed enormously, and we are curious who will fill this power vacuum. As browser-based mining is not anywhere near as profitable as it was in early 2018, we believe that singular cryptojacking activity -- by individual website owners -- will decrease. However, we expect adversaries to find possibilities of deploying cryptojacking at an even larger scale to still be profitable. This stresses the importance of researching campaigns, as the reuse of techniques, tactics and procedures in deploying them provides an effective angle to detect and mitigate these malicious activities. With prices decreasing throughout 2018, one would expect that this problem will eventually solve itself. Apart from the discontinuation of Coinhive, there is no clear indication that this is the case, as Monero prices have started to recover in the first months of 2019. If this trend continues, we expect to experience another outbreak of large cryptojacking campaigns, as robust defenses are still not widely implemented.

Hugo L. J. Bijmans - One of the best experts on this subject based on the ideXlab platform.

  • CCS - Just the Tip of the Iceberg: Internet-Scale Exploitation of Routers for Cryptojacking
    Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, 2019
    Co-Authors: Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr
    Abstract:

    The release of an efficient browser-based cryptominer, as introduced by Coinhive in 2017, has quickly spread throughout the web either as a new source of revenue for websites or exploited within the context of hacks and malicious advertisements. Several studies have analyzed the Alexa Top 1M and found 380 - 3,200 (0.038% - 0.32%) to be actively mining, with an estimated $41,000 per month revenue for the top 10 perpetrators. While placing a cryptominer on a popular website supplies considerable returns from its visitors' web browsers, it only generates revenue while a client is visiting the page. Even though large popular websites attract millions of visitors, the relatively low number of exploiting websites limits the total revenue that can be made. In this paper, we report on a new attack vector that drastically overshadows all existing cryptojacking activity discovered to date. Through a firmware vulnerability in MikroTik routers, cyber criminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing web connection. Thus, every web page visited by any user behind an infected router would mine to profit the criminals. Based on NetFlows recorded in a Tier 1 Network, semiweekly crawls and telescope traffic, we followed their activities over a period of 10 months, and report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, approximately 70% of all MikroTik devices deployed worldwide. We observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. Our results show that cryptojacking through MITM attacks is highly lucrative, a factor of 30 more than previous attack vectors.

  • USENIX Security Symposium - Inadvertently Making Cyber Criminals Rich: A Comprehensive Study of Cryptojacking Campaigns at Internet Scale
    2019
    Co-Authors: Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr
    Abstract:

    Cryptojacking, a phenomenon also known as drive-by cryptomining, involves stealing computing power from others to be used in illicit cryptomining. While first observed as host-based infections with low activity, the release of an efficient browser-based cryptomining application -- as introduced by Coinhive in 2017 -- has skyrocketed cryptojacking activity in recent years. This novel method of monetizing Web activity attracted both website owners and cybercriminals seeking new methods to profit from. Website owners installed a cryptominer on their domains, while cybercriminals deployed cryptominers in large campaigns spread over numerous domains. Several studies developed detection methods to identify these browser-based cryptominers on websites, but none of these studies focused on the extent and coordination of campaigns deployed by adversaries. Furthermore, the prevalence of cryptojacking on websites is not well estimated yet and the potentially largest attack vector -- a man-in-the-middle attack -- has never been researched before. In this thesis, we perform multiple large studies on cryptojacking to fill these gaps. After crawling a random sample of 49M domains, 20% of the Internet, we conclude that cryptojacking is present on 0.011% of all domains and that adult content is the most prevalent category of websites affected. We show that this percentage is significantly larger in the popular part of the Internet. This led to the conclusion that surveying solely domains listed in the Alexa Top 1M to estimate cryptojacking prevalence results in an overestimation of the problem. Furthermore, we show that infection rates on different Top Level Domains (TLDs) differ widely, as the Russian zone is home to a disproportionate number of cryptojacking domains, while other large TLDs -- such as .com -- show a significantly lower number of infections. In another crawl, we have identified 204 cryptojacking campaigns on websites, an order of magnitude more than previous work, which indicates that the extent of these campaigns is heavily underestimated. The results of the two crawls combined reveal that 48% of all cryptojacking activity on websites is organized. The identified campaigns ranged in sizes from only 5 to 987 websites and we discovered that cybercriminals have chosen third-party software -- such as WordPress and Drupal -- as their method of choice for spreading cryptojacking infections efficiently. With a novel method of using NetFlow data recorded in a Tier 1 Network, we estimated the popularity of mining applications, which showed that while Coinhive has a larger installed base, CoinImp WebSocket proxies were digesting significantly more traffic in the second half of 2018. We have reported about a new attack vector that drastically overshadows all other cryptojacking activity. Through a firmware vulnerability in MikroTik routers, cybercriminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing Web connection. Thus, every Web page visited by any user behind an infected router would mine to profit the adversaries. Based on the aforementioned NetFlow data, weekly third-party crawls and Network telescope traffic, we were able to follow their activities over a period of 10 months. We report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, which is approximately 70% of all MikroTik devices deployed in the world. During the peak of this attack, more than 440K routers were infected concurrently. We have discovered that half of the infected routers are patched within 18 days after compromise, but 30% of the infections last longer than 50 days. Additionally, we observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. The combination of datasets allowed us to link tens of seemingly different infections to one actor. Our analysis of cryptojacking with a focus on organized campaigns has shown that cybercriminals have successfully discovered a new method for monetary gain. With the discontinuation of Coinhive due to decreased Monero prices in March 2019, the cryptojacking landscape has changed enormously, and we are curious who will fill this power vacuum. As browser-based mining is not anywhere near as profitable as it was in early 2018, we believe that singular cryptojacking activity -- by individual website owners -- will decrease. However, we expect adversaries to find possibilities of deploying cryptojacking at an even larger scale to still be profitable. This stresses the importance of researching campaigns, as the reuse of techniques, tactics and procedures in deploying them provides an effective angle to detect and mitigate these malicious activities. With prices decreasing throughout 2018, one would expect that this problem will eventually solve itself. Apart from the discontinuation of Coinhive, there is no clear indication that this is the case, as Monero prices have started to recover in the first months of 2019. If this trend continues, we expect to experience another outbreak of large cryptojacking campaigns, as robust defenses are still not widely implemented.

Christophe Diot - One of the best experts on this subject based on the ideXlab platform.

  • INFOCOM - Analysis of point-to-point packet delay in an operational Network
    Computer Networks, 2007
    Co-Authors: Baek-young Choi, Sue Moon, Zhi-li Zhang, Konstantina Papagiannaki, Christophe Diot
    Abstract:

    In this paper we perform a detailed analysis of point-to-point packet delay in an operational Tier-1 Network. The point-to-point delay is the time between a packet entering a router in one PoP (an ingress point) and its leaving a router in another PoP (an egress point). It measures the one-way delay experienced by packets from an ingress point to an egress point across an ISP's Network and provides the most basic information regarding the delay performance of the ISP's Network. Using packet traces captured in the operational Network, we obtain precise point-to-point packet delay measurements and analyze the various factors affecting them. Through a simple, step-by-step, systematic methodology and careful data analysis, we identify the major Network factors that contribute to point-to-point packet delay and characterize their effect on the Network delay performance. Our findings are: 1) delay distributions vary greatly in shape, depending on the path and link utilization; 2) after constant factors dependent only on the path and packet size are removed, the 99th percentile variable delay remains under 1 ms over several hops and under link utilization below 90% on a bottleneck; 3) a very small number of packets experience very large delay in short bursts

  • AnalysisofPoint-To-PointPacketDelayinanOperationalNetwork ?
    2006
    Co-Authors: Baek-young Choi, Sue Moon, Zhi-li Zhang, Konstantina Papagiannaki, Christophe Diot
    Abstract:

    In this paper we perform a detailed analysis of point-to-point packet delay in an operational Tier-1 Network. The point-to-point delay is the time experienced by a packet from an ingress to an egress point in an ISP, and it provides the most basic information regarding the delay performance of the ISP’s Network. Using packet traces captured in the operational Network, we obtain precise point-to-point packet delay measurements and analyze the various factors affecting them. Through a simple, step-by-step, systematic methodology and careful data analysis, we identify the major Network factors that contribute to point-to-point packet delay and characterize their effect on the Network delay performance. Our findings are: 1) delay distributions vary greatly in shape, depending on the path and link utilization; 2) after constant factors dependent only on the path and packet size are removed, the 99th percentile variable delay remains under 1 ms over several hops and under link utilization below 90% on a bottleneck; 3) a very small number of packets experience very large delay in short bursts.

  • SIGMETRICS - The impact of BGP dynamics on intra-domain traffic
    Proceedings of the joint international conference on Measurement and modeling of computer systems - SIGMETRICS 2004 PERFORMANCE 2004, 2004
    Co-Authors: Sharad Agarwal, Chen-nee Chuah, Supratik Bhattacharyya, Christophe Diot
    Abstract:

    Recent work in Network traffic matrix estimation has focused on generating router-to-router or PoP-to-PoP (Point-of-Presence) traffic matrices within an ISP backbone from Network link load data. However, these estimation techniques have not considered the impact of inter-domain routing changes in BGP (Border Gateway Protocol). BGP routing changes have the potential to introduce significant errors in estimated traffic matrices by causing traffic shifts between egress routers or PoPs within a single backbone Network. We present a methodology to correlate BGP routing table changes with packet traces in order to analyze how BGP dynamics affect traffic fan-out within a large "Tier-1" Network. Despite an average of 133 BGP routing updates per minute, we find that BGP routing changes do not cause more than 0.03% of ingress traffic to shift between egress PoPs. This limited impact is mostly due to the relative stability of Network prefixes that receive the majority of traffic -- 0.05% of BGP routing table changes affect intra-domain routes for prefixes that carry 80% of the traffic. Thus our work validates an important assumption underlying existing techniques for traffic matrix estimation in large IP Networks.

  • INFOCOM - Inferring TCP connection characteristics through passive measurements
    IEEE INFOCOM 2004, 1
    Co-Authors: Sharad Jaiswal, Gianluca Iannaccone, Christophe Diot, J. Kurose, Don Towsley
    Abstract:

    We propose a passive measurement methodology to infer and keep track of the values of two important variables associated with a TCP connection: the sender's congestion window (cwnd) and the connection round trip time (RTT). Together, these variables provide a valuable diagnostic of end-user-perceived Network performance. Our methodology is validated via both simulation and concurrent active measurements, and is shown to be able to handle various flavors of TCP. Given our passive approach and measurement points within a Tier-1 Network provider, we are able to analyze more than 10 million connections, with senders located in more than 45% of the autonomous systems in today's Internet. Our results indicate that sender throughput is frequently limited by a lack of data to send, that the TCP congestion control flavor often has minimal impact on throughput, and that the vast majority of connections do not experience significant variations in RTT during their lifetime

Sebastien Tandel - One of the best experts on this subject based on the ideXlab platform.

  • quantifying the bgp routes diversity inside a Tier 1 Network
    International IFIP-TC Networking Conference, 2006
    Co-Authors: Steve Uhlig, Sebastien Tandel
    Abstract:

    Many large ISP Networks today rely on route-reflection [1] to allow their iBGP to scale. Route-reflection was officially introduced to limit the number of iBGP sessions, compared to the $\frac{n\times(n-1)}{2}$ sessions required by an iBGP full-mesh. Besides its impact on the number of iBGP sessions, route-reflection has consequences on the diversity of the routes known to the routers inside an AS. In this paper, we quantify the diversity of the BGP routes inside a Tier-1 Network. Our analysis shows that the use of route-reflection leads to a very poor route diversity compared to an iBGP full-mesh. Most routers inside a Tier-1 Network know only a single external route in eBGP origin. We identify two causes for this lack of diversity. First, some routes are never selected as best by any router inside the Network, but are known only to some border routers. Second, among the routes that are selected as best by at least one other router, a few are selected as best by a majority of the routers, preventing the propagation of many routes inside the AS. We show that the main reason for this diversity loss is how BGP chooses the best routes among those available inside the AS.

  • Networking - Quantifying the BGP routes diversity inside a Tier-1 Network
    NETWORKING 2006. Networking Technologies Services and Protocols; Performance of Computer and Communication Networks; Mobile and Wireless Communication, 2006
    Co-Authors: Steve Uhlig, Sebastien Tandel
    Abstract:

    Many large ISP Networks today rely on route-reflection [1] to allow their iBGP to scale. Route-reflection was officially introduced to limit the number of iBGP sessions, compared to the $\frac{n\times(n-1)}{2}$ sessions required by an iBGP full-mesh. Besides its impact on the number of iBGP sessions, route-reflection has consequences on the diversity of the routes known to the routers inside an AS. In this paper, we quantify the diversity of the BGP routes inside a Tier-1 Network. Our analysis shows that the use of route-reflection leads to a very poor route diversity compared to an iBGP full-mesh. Most routers inside a Tier-1 Network know only a single external route in eBGP origin. We identify two causes for this lack of diversity. First, some routes are never selected as best by any router inside the Network, but are known only to some border routers. Second, among the routes that are selected as best by at least one other router, a few are selected as best by a majority of the routers, preventing the propagation of many routes inside the AS. We show that the main reason for this diversity loss is how BGP chooses the best routes among those available inside the AS.

Baek-young Choi - One of the best experts on this subject based on the ideXlab platform.

  • Analysis of Point-To-Point Delay in an Operational Backbone
    Scalable Network Monitoring in High Speed Networks, 2011
    Co-Authors: Baek-young Choi, Zhi-li Zhang
    Abstract:

    In this chapter, we perform a detailed analysis of point-to-point packet delay in an operational Tier-1 Network. The point-to-point delay is the time between a packet entering a router in one PoP (an ingress point) and its leaving a router in another PoP (an egress point). It measures the one-way delay experienced by packets from an ingress point to an egress point across a carrier Network and provides the most basic information regarding the delay performance of the carrier Network. Using packet traces captured in the operational Network, we obtain precise pointto- point packet delay measurements and analyze the various factors affecting them. Through a simple, step-by-step, systematic methodology and careful data analysis, we identify the major Network factors that contribute to point-to-point packet delay and characterize their effect on the Network delay performance. Our findings are: 1) delay distributions vary greatly in shape, depending on the path and link utilization; 2) after constant factors dependent only on the path and packet size are removed, the 99th percentile variable delay remains under 1 ms over several hops and under link utilization below 90% on a bottleneck; 3) a very small number of packets experience very large delay in short bursts.

  • INFOCOM - Analysis of point-to-point packet delay in an operational Network
    Computer Networks, 2007
    Co-Authors: Baek-young Choi, Sue Moon, Zhi-li Zhang, Konstantina Papagiannaki, Christophe Diot
    Abstract:

    In this paper we perform a detailed analysis of point-to-point packet delay in an operational Tier-1 Network. The point-to-point delay is the time between a packet entering a router in one PoP (an ingress point) and its leaving a router in another PoP (an egress point). It measures the one-way delay experienced by packets from an ingress point to an egress point across an ISP's Network and provides the most basic information regarding the delay performance of the ISP's Network. Using packet traces captured in the operational Network, we obtain precise point-to-point packet delay measurements and analyze the various factors affecting them. Through a simple, step-by-step, systematic methodology and careful data analysis, we identify the major Network factors that contribute to point-to-point packet delay and characterize their effect on the Network delay performance. Our findings are: 1) delay distributions vary greatly in shape, depending on the path and link utilization; 2) after constant factors dependent only on the path and packet size are removed, the 99th percentile variable delay remains under 1 ms over several hops and under link utilization below 90% on a bottleneck; 3) a very small number of packets experience very large delay in short bursts

  • AnalysisofPoint-To-PointPacketDelayinanOperationalNetwork ?
    2006
    Co-Authors: Baek-young Choi, Sue Moon, Zhi-li Zhang, Konstantina Papagiannaki, Christophe Diot
    Abstract:

    In this paper we perform a detailed analysis of point-to-point packet delay in an operational Tier-1 Network. The point-to-point delay is the time experienced by a packet from an ingress to an egress point in an ISP, and it provides the most basic information regarding the delay performance of the ISP’s Network. Using packet traces captured in the operational Network, we obtain precise point-to-point packet delay measurements and analyze the various factors affecting them. Through a simple, step-by-step, systematic methodology and careful data analysis, we identify the major Network factors that contribute to point-to-point packet delay and characterize their effect on the Network delay performance. Our findings are: 1) delay distributions vary greatly in shape, depending on the path and link utilization; 2) after constant factors dependent only on the path and packet size are removed, the 99th percentile variable delay remains under 1 ms over several hops and under link utilization below 90% on a bottleneck; 3) a very small number of packets experience very large delay in short bursts.

  • Scalable Network traffic and performance monitoring
    2003
    Co-Authors: Zhi-li Zhang, Baek-young Choi
    Abstract:

    Network monitoring serves as basis for a wide scope of Network operation, engineering and management. Precise Network monitoring involves inspecting every packet traversing in a Network. However, it is infeasible in today's and future high-speed Networks, due to significant overheads of processing, storing, and transferring measured data. Therefore, scalable Network monitoring techniques are in urgent need. This thesis addresses the scalability issue of Network monitoring from both traffic and performance perspectives. On scalable traffic monitoring, we propose sampling techniques for total load and flow measurement. In order to develop accurate and efficient measurement schemes, we study various aspects of traffic characteristics and their impacts on packet sampling. We find that static sampling does not adjust itself to dynamic traffic conditions, yielding often erroneous estimations or excessive oversampling. We develop the adaptive random sampling technique for total load estimation, that determines the sampling probability adaptively according to traffic condition. Then, we enhance the adaptive sampling technique to measure traffic in flow level. Flow measurement is a particularly challenging problem, since flows arrive at random time, stay for random duration, and their rates fluctuate over time. Those characteristics make it hard to decide a sampling interval where sampling probability is adapted, and to define a large flow pragmatically. Through a stratified approach, we estimate large flows accurately, regardless of their arrival times, durations, and rate variabilities during their life times. On practical performance monitoring, we investigate issues around Network delay. We first perform a detailed analysis of point-to-point packet delay in an operational Tier-1 Network. Through a systematic methodology and careful analysis, we identify the major factors that contribute to point-to-point delay, and characterize their effect on the Network delay performance. Next, we identify high quantile as a meaningful metric in summarizing a delay distribution. Then, we propose an active sampling scheme to estimate a high quantile of a delay distribution with bounded error. We finally show that active probing is the most scalable approach to delay measurement. The validation of our proposed schemes and analysis of Network traffic and performance presented in this thesis are conducted with real operational Network traces.