【24h】

FIRE: FInding Rogue nEtworks

机译:火:寻找盗贼网络

获取原文

摘要

For many years, online criminals have been able to conduct their illicit activities by masquerading behind disreputable Internet Service Providers (ISPs). For example, organizations such as the Russian Business Network (RBN), Atrivo (a.k.a., Intercage), McColo, and most recently, the Triple Fiber Network (3FN) operated with impunity, providing a safe haven for Internet criminals for their own financial gain. What primarily sets these ISPs apart from others is the significant longevity of the malicious activities on their networks and the apparent lack of action taken in response to abuse reports. Interestingly, even though the Internet provides a certain degree of anonymity, such ISPs fear public attention. Once exposed, rogue networks often cease their malicious activities quickly, or are de-peered (disconnected) by their upstream providers. As a result, the Internet criminals are forced to relocate their operations. In this paper, we present FIRE, a novel system to identify and expose organizations and ISPs that demonstrate persistent, malicious behavior. The goal is to isolate the networks that are consistently implicated in malicious activity from those that are victims of compromise. To this end, FIRE actively monitors botnet communication channels, drive-by-download servers, and phishing web sites. This data is refined and correlated to quantify the degree of malicious activity for individual organizations. We present our results in real-time via the website maliciousnetworks.org. These results can be used to pinpoint and to track the activity of rogue organizations, preventing criminals from establishing strongholds on the Internet. Also, the information can be compiled into a null-routing blacklist to immediately halt traffic from malicious networks.
机译:多年来,在线犯罪分子通过伪装成名的互联网服务提供商(ISP)来进行非法活动。例如,俄罗斯商业网络(RBN),Atrivo(aka,Intercage),McColo等组织,以及最近的三重光纤网络(3FN)不受惩罚地运作,为互联网犯罪分子提供了避难所,以其自身的经济利益。这些ISP与其他ISP的主要区别在于其网络上恶意活动的寿命很长,并且显然没有采取措施应对滥用报告。有趣的是,即使Internet提供了一定程度的匿名性,此类ISP也担心公众的注意。一旦暴露,恶意网络通常会迅速停止其恶意活动,或者被上游提供商取消对等(断开连接)。结果,互联网罪犯被迫转移他们的行动。在本文中,我们介绍了FIRE,这是一种新颖的系统,用于识别和暴露表现出持续性恶意行为的组织和ISP。目的是将始终与恶意活动相关的网络与遭受破坏的网络隔离开。为此,FIRE主动监视僵尸网络通信通道,按下载驱动的服务器和网络钓鱼网站。此数据经过精炼和关联,以量化各个组织的恶意活动程度。我们通过恶意网站网站实时显示我们的结果。这些结果可用于查明和跟踪流氓组织的活动,从而防止犯罪分子在互联网上建立据点。而且,该信息可以被编译为一个无效路由的黑名单,以立即阻止来自恶意网络的流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号