Medium Interaction Honeypots

Medium Interaction Honeypots
复制标题

中等交互蜜罐

DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
Georg Wicherski
Georg Wicherski
中科院分区:
--
文献类型:
--
作者:
Georg Wicherski

文献摘要

被引文献

相似文献

自从互联网作为大规模计算机网络存在以来,自主传播恶意软件一直是互联网社区的全球威胁。这种威胁的一个特化是僵尸网络。最近僵尸网络商业化的趋势使情况变得更加糟糕。本文档概述了现有的不同捕获恶意软件(尤其是机器人)的方法的弱点,并展示了中等交互蜜罐如何解决这些问题。它评估了迄今为止中等交互蜜罐的成功,并另外指出了一些其他相关工作。 1 问题:僵尸网络 除垃圾邮件外,当今互联网面临的最大问题之一是自动传播恶意软件。有些恶意软件的编写只是为了证明作者的概念或教育,而其他恶意软件的编写只是出于破坏性的意图。然而,最大的威胁是远程控制后门造成的。它们不仅允许高度高级的商业间谍活动,最近的威胁甚至对最终客户的计算机也变得至关重要。许多受感染节点的可控网络目前被称为僵尸网络 [1],因为其中大多数即使在今天仍然基于 IRC 控制,并且非人类、可控 IRC 仆人(即使不是恶意的)的早期术语是机器人。然而,现在正在出现用于命令和控制此类僵尸网络的新协议,其中最广泛的 IRC 替代方案是 HTTP。另一个有趣的趋势是使用 DNS 作为命令和控制协议,尽管这尚未得到广泛使用。僵尸网络对当今的互联网社区构成严重威胁,主要原因有两个:首先,单个僵尸网络可用的资源总量非常巨大,足以造成严重损害。由 5,000 个 DSL 6MBit 僵尸程序组成的僵尸网络,其公共上行速率为 576 kbit/s,理论总带宽为 2812.5 MBit/s。现在僵尸网络控制着多达 50,000 台主机,实际带宽达到 20 GBit/s,很明显,任何网络托管商甚至上游提供商都可以通过分布式拒绝服务攻击来摧毁。从 1997 年到 2003 年,这种通过僵尸网络进行的滥用最为常见,因为它不需要任何真正的技术复杂性。控制如此多的资源带来的另一个重大风险是发送和传递大量垃圾邮件。
Autonomously spreading malware has been a global threat to the Internet Community ever since the existence of the Internet as a large-scale computer network. A specialization of this threat are botnets; recent trends towards commercialization of botnets made the situation even worse. This document outlines the weaknesses of different existing approaches to catch malware – especially bots – and shows how Medium Interaction Honeypots solved these problems. It evaluates the success of Medium Interaction Honeypots so far and additionally points out some other related work. 1 The Problem: Botnets One of the biggest problems the Internet is facing today – besides spam – is autonomously spreading malware. Some malware was written solely for proof of concept or education of the author, other malware was written with solely destructive intentions in mind. The biggest threat is however posed by remotely controllable backdoors. They not only allow commercial industry espionage on a highly advanced level, recent threats have become critical even to the end customer’s computer. Controllable networks of many infected nodes are currently referred to as botnets [1] as most of these are even today still based upon the IRC control and an early term for non-human, controllable IRC servants (even though not malicious) was bot. However, new protocols are now emerging for command and control of such botnets, with the most widespread alternative to IRC being HTTP. Another interesting trend is to use DNS as command and control protocol, although this is not in widespread use yet. Botnets pose a severe threat to today’s Internet community for two main reasons: first of all, the sum of resources available by a single botnet is so immense that they can cause severe damages. A botnet of 5,000 DSL 6MBit bots with a common upstream of 576 kbit/s has a total theoretical bandwidth of 2812.5 MBit/s. Now that there are botnets controling up to 50,000 hosts which yields to a practical bandwidth of 20 GBit/s, it is obvious that any webhoster or even upstream provider can be taken down with a Distributed Denial of Service attack. This type of abuse through botnets was the most common from 1997 through 2003 as it did not require any real technical sophistication. Another critical risk created by the control of so many resources is the sending and delivering huge amounts of spam.