首页> 外文会议>International symposium on research in attacks, intrusion, and defenses >Connected Colors: Unveiling the Structure of Criminal Networks
【24h】

Connected Colors: Unveiling the Structure of Criminal Networks

机译:关联的色彩:揭露犯罪网络的结构

获取原文

摘要

In this paper we study the structure of criminal networks, groups of related malicious infrastructures that work in concert to provide hosting for criminal activities. We develop a method to construct a graph of relationships between malicious hosts and identify the underlying criminal networks, using historic assignments in the DNS. We also develop methods to analyze these networks to identify general structural trends and devise strategies for effective remediation through takedowns. We then apply these graph construction and analysis algorithms to study the general threat landscape, as well as four cases of sophisticated criminal networks. Our results indicate that in many cases, criminal networks can be taken down by de-registering as few as five domain names, removing critical communication links. In cases of sophisticated criminal networks, we show that our analysis techniques can identify hosts that are critical to the network's functionality and estimate the impact of performing network takedowns in remediating the threats. In one case, disabling 20% of a criminal network's hosts would reduce the overall volume of successful DNS lookups to the criminal network by as much as 70%. This measure can be interpreted as an estimate of the decrease in the number of potential victims reaching the criminal network that would be caused by such a takedown strategy.
机译:在本文中,我们研究犯罪网络的结构,相关的恶意基础结构组,这些组协同工作以为犯罪活动提供托管。我们开发了一种方法,可以使用DNS中的历史分配来构造恶意主机之间的关系图,并识别潜在的犯罪网络。我们还开发了分析这些网络的方法,以确定总体结构趋势,并设计了通过删除进行有效补救的策略。然后,我们将使用这些图构造和分析算法来研究一般的威胁态势以及四种复杂的犯罪网络案例。我们的结果表明,在许多情况下,只需注销五个域名即可删除犯罪网络,从而删除关键的通信链接。在复杂的犯罪网络中,我们证明了我们的分析技术可以识别对网络功能至关重要的主机,并估计执行网络拆卸对补救威胁的影响。在一种情况下,禁用犯罪网络主机的20%将使对犯罪网络成功进行DNS查找的总数量减少多达70%。这项措施可以解释为对这种删除策略可能导致到达犯罪网络的潜在受害者人数减少的估计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号