首页> 外文会议>2012 Seventh International Conference on P2P, Parallel, Grid, Cloud and Internet Computing. >Assessing Trade-Offs between Stealthiness and Node Recruitment Rates in Peer-to-Peer Botnets
【24h】

Assessing Trade-Offs between Stealthiness and Node Recruitment Rates in Peer-to-Peer Botnets

机译:评估对等僵尸网络的隐身性和节点招募率之间的权衡

获取原文
获取原文并翻译 | 示例

摘要

Botnets denote collections of compromised computers under adversary control and, although early botnets using centralized command and control (C&C) structures were fairly easily defeated, botnets remain a serious global security threat. in part, this is due to the evolution within the adversarial communities using highly diffuse decentralized peer-to-peer (P2P) based C&C within modern botnets, which has proven far more difficult to address. the resulting increased botnet resilience though comes at the cost of placing the bots further from the botmasterâs direct control, thereby, increasing the time required to recruit subsets of bots to specific malicious tasks, (i.e., to send spam, engage in a DDOS attack, etc.). This work explores the specific tradeoffs that occur between achievable bot recruitment rates and overall botnet stealthiness within P2P structured botnets. It is shown that rapid recruitment of nodes (or bots) leads directly to an order of magnitude increase in the botnetâs generated network traffic, which makes the botnet significantly more visible (and susceptible) to defensive counter-measures. Kademlia is used through out this work as the exemplar P2P protocol as, within the real-world, Kademlia has proven to provide an effective C&C mechanism for a number of the longer-lived botnets.
机译:僵尸网络表示受到敌方控制的受感染计算机的集合,尽管使用集中式命令和控制(C& C)结构的早期僵尸网络相当容易被击败,但僵尸网络仍然是严重的全球安全威胁。在某种程度上,这是由于对抗性社区内部的发展,其在现代僵尸网络中使用了高度分散的基于点对点(P2P)的C& C,这被证明很难解决。导致的僵尸网络弹性增强的代价是,使僵尸程序远离僵尸程序直接控制,从而增加了将僵尸程序子集招募到特定恶意任务所需的时间,例如,发送垃圾邮件,进行DDOS攻击,等等。)。这项工作探讨了在P2P结构化僵尸网络内可实现的僵尸网络招募率与僵尸网络总体隐身性之间的具体权衡。结果表明,快速招募节点(或僵尸网络)直接导致僵尸网络生成的网络流量增加一个数量级,这使僵尸网络对于防御性对策而言更加明显(并且更容易受到攻击)。在整个工作中,Kademlia被用作示例性P2P协议,因为在现实世界中,Kademlia被证明可以为许多寿命较长的僵尸网络提供有效的C& C机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号