首页> 外文期刊>International Journal of Information Security >New facets of mobile botnet: architecture and evaluation
【24h】

New facets of mobile botnet: architecture and evaluation

机译:移动僵尸网络的新方面:架构和评估

获取原文
获取原文并翻译 | 示例
           

摘要

It is without a doubt that botnets pose a growing threat to the Internet, with DDoS attacks of any kind carried out by botnets to be on the rise. Nowadays, botmasters rely on advanced Command and Control (C&C) infrastructures to achieve their goals and most importantly to remain undetected. This work introduces two novel botnet architectures that consist only of mobile devices and evaluates both their impact in terms of DNS amplification and TCP flooding attacks, and their cost pertaining to the maintenance of the C&C channel. The first one puts forward the idea of using a continually changing mobile HTTP proxy in front of the botherder, while the other capitalizes on DNS protocol as a covert channel for coordinating the botnet. That is, for the latter, the messages exchanged among the bots and the herder appear as legitimate DNS transactions. Also, a third architecture is described and assessed, which is basically an optimized variation of the first one. Namely, it utilizes a mixed layout where all the attacking bots are mobile, but the proxy machines are typical PCs not involved in the actual attack. For the DNS amplification attack, which is by nature more powerful, we report an amplification factor that fluctuates between 32.7 and 34.1. Also, regarding the imposed C&C cost, we assert that it is minimal (about 0.25 Mbps) per bot in the worst case happening momentarily when the bot learns about the parameters of the attack.
机译:毫无疑问,僵尸网络对互联网构成了越来越大的威胁,僵尸网络进行的任何形式的DDoS攻击都在增加。如今,僵尸程序管理员依靠高级命令与控制(C&C)基础结构来实现其目标,最重要的是保持未被发现的状态。这项工作介绍了两个仅由移动设备组成的新颖的僵尸网络体系结构,并评估了它们在DNS放大和TCP泛洪攻击方面的影响,以及与维护C&C通道有关的成本。第一个提出了在麻烦之前使用不断变化的移动HTTP代理的想法,而另一个则利用DNS协议作为协调僵尸网络的隐性渠道。也就是说,对于后者,僵尸程序和牧民之间交换的消息显示为合法的DNS事务。另外,描述并评估了第三种架构,它基本上是第一种的优化变体。也就是说,它采用了混合布局,其中所有攻击机器人都可以移动,但代理计算机是不参与实际攻击的典型PC。对于本质上更强大的DNS放大攻击,我们报告了一个放大系数,该放大系数在32.7和34.1之间波动。此外,关于强制性C&C成本,我们断言,在最坏的情况下,当僵尸程序了解攻击参数时,每个僵尸程序的成本最低(约0.25 Mbps)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号