首页> 外文会议>International Computer Conference, Computer Society of Iran >GITCBot: A Novel Approach for the Next Generation of CC Malware
【24h】

GITCBot: A Novel Approach for the Next Generation of CC Malware

机译:gitcbot:下一代C&C恶意软件的新方法

获取原文

摘要

Online Social Networks (OSNs) attracted millions of users in the world. OSNs made adversaries more passionate to create malware variants to subvert the cyber defence of OSNs. Through various threat vectors, adversaries persuasively lure OSN users into installing malware on their devices at an enormous scale. One of the most horrendous forms of named malware is OSNs' botnets that conceal C&C information using OSNs' accounts of unaware users. In this paper, we present GITC (Ghost In The Cloud), which uses Telegram as a C&C server to communicate with threat actors and access targets' information in an undetectable way. Furthermore, we present our implementation of GITC. We show how GITC uses the encrypted telegram Application Programming Interface (API) to cover up records of the adversary connections to the target, and we discuss why current intrusion detection systems cannot detect GITC. In the end, we run some sets of experiments that confirm the feasibility of GITC.
机译:在线社交网络(OSNS)吸引了全球数百万用户。 OSNS使对手更加热情以创建恶意软件变体来颠覆osn的网络防御。 通过各种威胁向量,对手利用旨在以巨大的规模在其设备上安装恶意软件。 最可怕的名为恶意软件的形式之一是使用OSNS'不知用户帐户隐藏C&C信息的OSNS的僵尸网络。 在本文中,我们展示了Gitc(云中的Ghost),它使用电报作为C&C服务器以不可检测的方式与威胁演员和访问目标信息进行通信。 此外,我们展示了我们的GITC实施。 我们展示了Gitc如何使用加密的电报应用程序编程接口(API)来掩盖对目标的对手连接的记录,我们讨论了当前入侵检测系统无法检测到Gitc的原因。 最后,我们运行了一些实验,证实了Gitc的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号