首页> 外文会议>International Conference on Information and Communications Security >CoinBot: A Covert Botnet in the Cryptocurrency Network
【24h】

CoinBot: A Covert Botnet in the Cryptocurrency Network

机译:Coinbot:加密货币网络中的隐蔽僵尸网络

获取原文

摘要

Cryptocurrencies are a new form of digital asset and are being widely used throughout the world. A variety of cryptocurrency-based botnets have been proposed and developed to utilize cryptocurrencies as new command and control (C&C) platforms. Most existing cryptocurrency-based botnets are bonded with the cryptocurrency client, which generates abnormal P2P traffic that can be easily detected and blocked. In addition, the commands embedded in transaction records can be easily traced, since the transaction records in a cryptocurrency network are usually publicly available. In this paper, we propose CoinBot, a novel botnet that based on the cryptocurrency networks. CoinBot is characterized by low cost, high resilience, stealthiness, and anti-traceability. Different from other cryptocurrency-based botnet, CoinBot utilizes Web2.0 services to achieve a dynamic addressing service for obtaining commands. As such, there is no need to run a cryptocurrency wallet application and hardcode a botmaster's sensitive information in CoinBot, and the communications between the botmaster and the bots are hidden under legitimate HTTP/S traffic. Furthermore, we propose a cleaning scheme to prevent commands from being permanently recorded in the blockchain, thereby decreasing the risk of channel exposure. CoinBot is a generic model that can be applied to different kinds of cryptocurrency networks. We believe this model will be highly attractive to botmasters and could pose a considerable threat to cybersecurity. Therefore, we provide defensive suggestions to mitigate similar threats in the future.
机译:加密货币是一种新的数字资产形式,并在全世界广泛使用。已经提出了各种基于加密货的僵尸网络,并开发用于利用加密货币作为新命令和控制(C&C)平台。大多数现有的加密电流基僵尸网络与加密货币客户端绑定,这会产生可以容易地检测和阻止的异常P2P流量。此外,可以轻松跟踪嵌入在交易记录中的命令,因为加密电流网络中的交易记录通常可公开可用。在本文中,我们提出了一种基于密码货网络的新型僵尸网络的Coinbot。 Coinbot的特点是成本低,韧性高,隐身和抗可追溯性。 Coinbot与其他基于加密货币的僵尸网络不同,使用Web2.0服务来实现用于获取命令的动态寻址服务。因此,无需在Coinbot中运行加密货币钱包应用程序并解决Botmaster的敏感信息,并且Botmaster与机器人之间的通信隐藏在合法的HTTP / S流量下。此外,我们提出了一种清洁方案,以防止在区块链中永久记录的命令,从而降低信道曝光的风险。 Coinbot是一种通用模型,可以应用于不同类型的加密货网络。我们认为,这种模式对BotMasters非常有吸引力,可能对网络安全构成相当大的威胁。因此,我们提供防御性建议,以减轻未来的类似威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号