...
首页> 外文期刊>International Journal of Information Security >Hydras and IPFS: a decentralised playground for malware
【24h】

Hydras and IPFS: a decentralised playground for malware

机译:Hydras和IPFS:恶意软件的分散游乐场

获取原文
获取原文并翻译 | 示例

摘要

Modern malware can take various forms and has reached a very high level of sophistication in terms of its penetration, persistence, communication and hiding capabilities. The use of cryptography, and of covert communication channels over public and widely used protocols and services, is becoming a norm. In this work, we start by introducing Resource Identifier Generation Algorithms. These are an extension of a well-known mechanism called domain generation algorithms, which are frequently employed by cybercriminals for bot management and communication. Our extension allows, beyond DNS, the use of other protocols. More concretely, we showcase the exploitation of the InterPlanetary File System (IPFS). This is a solution for the “permanent web”, which enjoys a steadily growing community interest and adoption. The IPFS is, in addition, one of the most prominent solutions for blockchain storage. We go beyond the straightforward case of using the IPFS for hosting malicious content and explore ways in which a botmaster could employ it, to manage her bots, validating our findings experimentally. Finally, we discuss the advantages of our approach for malware authors, its efficacy and highlight its extensibility for other distributed storage services.
机译:现代恶意软件可以采取各种形式,并在其渗透,持久性,通信和隐藏能力方面达到了非常高的复杂性。使用密码术以及公共和广泛使用的协议和服务的隐蔽通信渠道正在成为一个常态。在这项工作中,我们首先介绍资源标识符生成算法。这些是一种称为域生成算法的众所周知的机制的扩展,其经常由网络犯罪分子用于机器人管理和通信。我们的扩展允许超越DNS,使用其他协议。更具体地说,我们展示了行星期性文件系统(IPF)的开发。这是“永久网络”的解决方案,它享有稳步增长的社区兴趣和采用。此外,IPF也是区块链存储最突出的解决方案之一。我们超越了使用IPF的直接案例,用于托管恶意内容,并探索Botmaster可以使用它的方式,管理她的机器人,通过实验验证我们的研究结果。最后,我们讨论了我们对恶意软件作者的方法的优势,其功效并突出了其对其他分布式存储服务的可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号