首页> 外文会议>European Symposium on Research in Computer Security >Understanding Cross-Channel Abuse with SMS-Spam Support Infrastructure Attribution
【24h】

Understanding Cross-Channel Abuse with SMS-Spam Support Infrastructure Attribution

机译:了解与SMS-SPAM支持基础架构归因的交叉渠道滥用

获取原文
获取外文期刊封面目录资料

摘要

Recent convergence of telephony with the Internet offers malicious actors the ability to craft cross-channel attacks that leverage both telephony and Internet resources. Bulk messaging services can be used to send unsolicited SMS messages to phone numbers. While the long-term properties of email spam tactics have been extensively studied, such behavior for SMS spam is not well understood. In this paper, we discuss a novel SMS abuse attribution system called CHURN. The proposed system is able to collect data about large SMS abuse campaigns and analyze their passive DNS records and supporting website properties. We used CHURN to systematically conduct attribution around the domain names and IP addresses used in such SMS spam operations over a five year time period. Using CHURN, we were able to make the following observations about SMS spam campaigns: (1) only 1% of SMS abuse domains ever appeared in public domain blacklists and more than 94% of the blacklisted domain names did not appear in such public blacklists for several weeks or even months after they were first reported in abuse complaints, (2) more than 40% of the SMS spam domains were active for over 100 days, and (3) the infrastructure that supports the abuse is surprisingly stable. That is, the same SMS spam domain names were used for several weeks and the IP infrastructure that supports these campaigns can be identified in a few networks and a small number of IPs, for several months of abusive activities. Through this study, we aim to increase the situational awareness around SMS spam abuse, by studying this phenomenon over a period of five years.
机译:最近与互联网的电话融合提供了恶意演员,该演员可以制作利用电话和互联网资源的交叉渠道攻击。批量消息服务可用于将未经请求的SMS消息发送到电话号码。虽然电子邮件垃圾邮件策略的长期属性已经过广泛研究,但短信垃圾邮件的行为并不能很好地理解。在本文中,我们讨论了一个名为Churn的新型短信滥用归因系统。建议的系统能够收集有关大型短信滥用活动的数据,并分析其被动DNS记录并支持网站属性。我们在五年的时间段内使用流失以系统地围绕这些短信垃圾邮件操作中使用的域名和IP地址进行归属。使用Churn,我们能够在公共领域黑名单中出现以下一个关于SMS垃圾邮件活动的观察:(1)只有1%的短信滥用域名出现在公共领域黑名单中,并且在此类公共黑名单中未出现超过94%的黑名单域名。在滥用滥用投诉中首次报告的几周甚至几个月后,超过40%的SMS垃圾邮件域有超过100天,并且(3)支持滥用的基础设施令人惊讶。也就是说,使用相同的SMS垃圾邮件域名数周和支持这些广告系列的IP基础设施可以在几个网络中识别出几个月的几个月的滥用活动。通过这项研究,我们的目标是通过在五年内研究这种现象来提高SMS垃圾邮件滥用的情境意识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号