首页> 外文会议>Detection of intrusions and malware, and vulnerability assessment >Take a Deep Breath: A Stealthy, Resilient and Cost-Effective Botnet Using Skype
【24h】

Take a Deep Breath: A Stealthy, Resilient and Cost-Effective Botnet Using Skype

机译:深吸一口气:使用Skype的隐身,灵活且经济高效的僵尸网络

获取原文
获取原文并翻译 | 示例

摘要

Skype is one of the most used P2P applications on the Internet: VoIP calls, instant messaging, SMS and other features are provided at a low cost to millions of users. Although Skype is a closed source application, an API allows developers to build custom plugins which interact over the Skype network, taking advantage of its reliability and capability to easily bypass firewalls and NAT devices. Since the protocol is completely undocumented, Skype traffic is particularly hard to analyze and to reverse engineer. We propose a novel botnet model that exploits an overlay network such as Skype to build a parasitic overlay, making it extremely difficult to track the botmaster and disrupt the botnet without damaging legitimate Skype users. While Skype is particularly valid for this purpose due to its abundance of features and its widespread installed base, our model is generically applicable to distributed applications that employ overlay networks to send direct messages between nodes (e.g., peer-to-peer software with messaging capabilities). We are convinced that similar botnet models are likely to appear into the wild in the near future and that the threats they pose should not be underestimated. Our contribution strives to provide the tools to correctly evaluate and understand the possible evolution and deployment of this phenomenon.
机译:Skype是Internet上最常用的P2P应用程序之一:VoIP呼叫,即时消息,SMS和其他功能以低成本为数百万用户提供。尽管Skype是封闭源应用程序,但API允许开发人员构建自定义插件,这些插件可以通过Skype网络进行交互,并利用其可靠性和功能轻松绕过防火墙和NAT设备。由于该协议完全没有记录,因此Skype流量特别难以分析和反向工程。我们提出了一种新颖的僵尸网络模型,该模型利用诸如Skype之类的覆盖网络来构建寄生覆盖,这使得在不损害合法的Skype用户的情况下,很难跟踪僵尸网络和破坏僵尸网络。尽管Skype因其功能丰富和广泛的安装基础而特别适用于此目的,但我们的模型通常适用于使用覆盖网络在节点之间发送直接消息的分布式应用程序(例如,具有消息传递功能的对等软件) )。我们坚信,类似的僵尸网络模型可能会在不久的将来流行开来,因此,它们所构成的威胁不容小under。我们的贡献致力于提供工具来正确评估和理解此现象的可能演变和部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号