...
首页> 外文期刊>Computer communication review >ASwatch: An AS Reputation System to Expose Bulletproof Hosting ASes
【24h】

ASwatch: An AS Reputation System to Expose Bulletproof Hosting ASes

机译:ASwatch:一个AS信誉系统,用于公开防弹托管ASes

获取原文
获取原文并翻译 | 示例

摘要

Bulletproof hosting Autonomous Systems (ASes)-malicious ASes fully dedicated to supporting cybercrime-provide freedom and resources for a cyber-criminal to operate. Their services include hosting a wide range of illegal content, bot-net C&C servers, and other malicious resources. Thousands of new ASes are registered every year, many of which are often used exclusively to facilitate cybercrime. A natural approach to squelching bulletproof hosting ASes is to develop a reputation system that can identify them for takedown by law enforcement and as input to other attack detection systems (e.g., spam filters, botnet detection systems). Unfortunately, current AS reputation systems rely primarily on data-plane monitoring of malicious activity from IP addresses (and thus can only detect malicious ASes after attacks are underway), and are not able to distinguish between malicious and legitimate but abused ASes. As a complement to these systems, in this paper, we explore a fundamentally different approach to establishing AS reputation. We present ASwatch, a system that identifies malicious ASes using exclusively the control-plane (i.e., routing) behavior of ASes. ASwatch's design is based on the intuition that, in an attempt to evade possible detection and remediation efforts, malicious ASes exhibit "agile" control plane behavior (e.g., short-lived routes, aggressive re-wiring). We evaluate our system on known malicious ASes; our results show that ASwatch detects up to 93% of malicious ASes with a 5% false positive rate, which is reasonable to effectively complement existing defense systems.
机译:防弹托管自治系统(ASes)的恶意ASes完全致力于支持网络犯罪,从而为网络犯罪分子提供了运行的自由和资源。他们的服务包括托管各种非法内容,僵尸网络C&C服务器以及其他恶意资源。每年都有成千上万个新的AS被注册,其中许多经常专门用于促进网络犯罪。抑制防弹托管AS的一种自然方法是开发一种信誉系统,该信誉系统可以识别它们以供执法部门删除并作为其他攻击检测系统(例如垃圾邮件过滤器,僵尸网络检测系统)的输入。不幸的是,当前的AS信誉系统主要依靠来自IP地址的数据平面监视恶意活动(因此只能在攻击发生后才能检测到恶意AS),并且无法区分恶意和合法但滥用的AS。作为对这些系统的补充,我们在本文中探索了建立AS信誉的根本不同的方法。我们介绍了ASwatch,这是一种仅使用AS的控制平面(即路由)行为来识别恶意AS的系统。 ASwatch的设计基于这样的直觉,即为逃避可能的检测和补救工作,恶意AS表现出“敏捷”的控制平面行为(例如,寿命短的路由,主动重新布线)。我们在已知的恶意AS上评估我们的系统;我们的结果表明,ASwatch可以检测到高达93%的恶意AS,且误报率为5%,这对于有效补充现有防御系统是合理的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号