New facets of mobile botnet: architecture and evaluation

New facets of mobile botnet: architecture and evaluation
复制标题

DOI:
10.1007/s10207-015-0310-0
复制
发表时间:
2016-10
影响因子:
3.2
通讯作者:
M. Anagnostopoulos;G. Kambourakis;S. Gritzalis
M. Anagnostopoulos;G. Kambourakis;S. Gritzalis
中科院分区:
计算机科学4区
文献类型:
--
作者:
M. Anagnostopoulos;G. Kambourakis;S. Gritzalis

文献摘要

被引文献

相似文献

毫无疑问,僵尸网络对互联网构成了越来越大的威胁,僵尸网络进行的任何类型的DDoS攻击都在上升。如今,僵尸主机依赖于先进的命令和控制(C&C)基础设施来实现其目标,最重要的是保持不被发现。这项工作介绍了两种新的僵尸网络架构,只包括移动的设备,并评估其影响方面的DNS放大和TCP洪水攻击,其成本有关的C&C通道的维护。第一个提出了使用一个不断变化的移动的HTTP代理在前面的botherder的想法,而另一个利用DNS协议作为协调僵尸网络的隐蔽通道。也就是说,对于后者,机器人和牧民之间交换的消息看起来是合法的DNS交易。此外,第三个架构进行了描述和评估,这基本上是第一个优化的变化。也就是说,它采用混合布局,其中所有攻击机器人都是移动的,但代理机器是不参与实际攻击的典型PC。对于DNS放大攻击,它本质上更强大,我们报告的放大因子在32.7和34.1之间波动。此外,关于强加的C&C成本,我们断言,在最坏的情况下,当机器人了解攻击的参数时,每个机器人的C & C成本是最小的(约0.25 Mbps)。
It is without a doubt that botnets pose a growing threat to the Internet, with DDoS attacks of any kind carried out by botnets to be on the rise. Nowadays, botmasters rely on advanced Command and Control (C&C) infrastructures to achieve their goals and most importantly to remain undetected. This work introduces two novel botnet architectures that consist only of mobile devices and evaluates both their impact in terms of DNS amplification and TCP flooding attacks, and their cost pertaining to the maintenance of the C&C channel. The first one puts forward the idea of using a continually changing mobile HTTP proxy in front of the botherder, while the other capitalizes on DNS protocol as a covert channel for coordinating the botnet. That is, for the latter, the messages exchanged among the bots and the herder appear as legitimate DNS transactions. Also, a third architecture is described and assessed, which is basically an optimized variation of the first one. Namely, it utilizes a mixed layout where all the attacking bots are mobile, but the proxy machines are typical PCs not involved in the actual attack. For the DNS amplification attack, which is by nature more powerful, we report an amplification factor that fluctuates between 32.7 and 34.1. Also, regarding the imposed C&C cost, we assert that it is minimal (about 0.25 Mbps) per bot in the worst case happening momentarily when the bot learns about the parameters of the attack.