【24h】

Fast and Evasive Attacks: Highlighting the Challenges Ahead

机译:快速而躲避的攻击:突出显示未来的挑战

获取原文
获取原文并翻译 | 示例

摘要

Passive network monitors, known as telescopes or darknets, have been invaluable in detecting and characterizing malware outbreaks. However, as the use of such monitors becomes commonplace, it is likely that malware will evolve to actively detect and evade them. This paper highlights the threat of simple, yet effective, evasive attacks that undermine the usefulness of passive monitors. Our results raise an alarm to the research and operational communities to take proactive countermeasures before we are forced to defend against similar attacks appearing in the wild. Specifically, we show how lightweight, coordinated sampling of the IP address space can be used to successfully detect and evade passive network monitors. Equally troubling is the fact that in doing so attackers can locate the "live" IP space clusters and divert malware scanning solely toward active networks. We show that evasive attacks exploiting this knowledge are also extremely fast, overtaking the entire vulnerable population within seconds.
机译:被动网络监控器(称为望远镜或暗网)在检测和表征恶意软件爆发方面具有不可估量的价值。但是,随着使用此类监视器变得司空见惯,恶意软件很可能会进化为主动检测和逃避它们。本文重点介绍了简单而有效的回避攻击的威胁,这些攻击破坏了被动监视器的有用性。我们的研究结果使研究人员和运营机构感到震惊,他们采取了积极的对策,然后才被迫防御野外出现的类似攻击。具体来说,我们展示了如何使用IP地址空间的轻量级协调采样来成功检测和逃避被动网络监视器。同样令人不安的是,攻击者可以通过这种方式找到“实时” IP空间集群,并将恶意软件扫描仅转移到活动网络。我们证明,利用这种知识进行的躲避攻击也非常快,几秒钟之内就可以取代整个弱势群体。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号