首页> 外文期刊>Computer Communications >Fluxing botnet command and control channels with URL shortening services
【24h】

Fluxing botnet command and control channels with URL shortening services

机译:通过URL缩短服务来融合botnet命令和控制通道

获取原文
获取原文并翻译 | 示例
       

摘要

URL shortening services (USSes), which provide short aliases to registered long URLs, have become popular owing to Twitter. Despite their popularity, researchers do not carefully consider their security problems. In this paper, we explore botnet models based on USSes to prepare for new security threats before they evolve. Specifically, we consider using USSes for alias flux to hide botnet command and control (C&C) channels. In alias flux, a botmaster obfuscates the IP addresses of his C&C servers, encodes them as URLs, and then registers them to USSes with custom aliases generated by an alias generation algorithm. Later, each bot obtains the encoded IP addresses by contacting USSes using the same algorithm. For USSes that do not support custom aliases, the botmaster can use shared alias lists instead of the shared algorithm. DNS-based botnet detection schemes cannot detect an alias flux botnet, and network-level detection and blacklisting of the fluxed aliases are difficult. We also discuss possible counter-measures to cope with these new threats and investigate operating USSes.
机译:URL缩短服务(USSes)为注册的长URL提供短别名,由于Twitter,它已经变得很流行。尽管很受欢迎,但研究人员并未仔细考虑其安全问题。在本文中,我们探索了基于USSes的僵尸网络模型,以在新的安全威胁发生之前做好准备。具体来说,我们考虑使用USSes作为别名通量来隐藏僵尸网络命令和控制(C&C)通道。在别名通量中,僵尸主机混淆了C&C服务器的IP地址,将它们编码为URL,然后使用别名生成算法生成的自定义别名将它们注册到USS。之后,每个漫游器都使用相同的算法通过与USS联系来获取编码的IP地址。对于不支持自定义别名的USS,僵尸网络管理员可以使用共享别名列表而不是共享算法。基于DNS的僵尸网络检测方案无法检测到别名通量僵尸网络,并且网络级别的检测和通量别名的黑名单很难。我们还将讨论可能的对策来应对这些新威胁并调查运行中的USS。

著录项

  • 来源
    《Computer Communications》 |2013年第3期|320-332|共13页
  • 作者

    Sangho Lee; Jong Kim;

  • 作者单位

    Department of Computer Science and Engineering, Pohang University of Science and Technology (POSTECH), Pohang, Republic of Korea;

    Division of IT Convergence Engineering, Pohang University of Science and Technology (POSTECH), Pohang, Republic of Korea;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    botnet; DNS; domain flux; URL shortening service;

    机译:僵尸网络DNS;磁通量URL缩短服务;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号