A Near Real-Time Scheme for Collecting and Analyzing IoT Malware Artifacts at Scale

A Near Real-Time Scheme for Collecting and Analyzing IoT Malware Artifacts at Scale
复制标题

DOI:
10.1145/3538969.3539009
复制
发表时间:
2022-08
期刊:
Proceedings of the 17th International Conference on Availability, Reliability and Security
影响因子:
--
通讯作者:
Joseph Khoury;Morteza Safaei Pour;E. Bou-Harb
Joseph Khoury;Morteza Safaei Pour;E. Bou-Harb
中科院分区:
其他
文献类型:
--
作者:
Joseph Khoury;Morteza Safaei Pour;E. Bou-Harb

文献摘要

被引文献

相似文献

物联网(IoT)僵尸网络恶意软件活动的长期扩散,加上安全漏洞的前所未有的增加,为犯罪者带来了新的机会,并在获取相关IoT恶意软件情报方面揭示了一系列新的障碍。物联网范式内的这种不足加剧了在很大程度上识别流行的物联网恶意软件威胁、物联网攻击的起源以及与物联网范式相关联的安全缺陷的能力。以前的工作已经广泛地研究了物联网恶意软件活动,但还没有大规模地分析恶意活动,以近实时地收集中心物联网工件,这些工件是理解并最终提升物联网生态系统安全态势所急需的。为此,我们在这项工作中提出了一个近实时的收集方案,以收集和分析大型物联网恶意软件工件,这对于了解普遍的网络安全风险至关重要。在这项工作中,我们利用一个由1670万个IP组成的大型网络望远镜作为一个广泛的蜜罐来检查恶意物联网探测器的证据。随后,我们采用欺骗技术来响应这些探测,并最终建立虚假连接来收集物联网恶意软件工件。在仅120小时的近实时测量中,我们提出的方案收集了来自30,190个恶意软件感染的物联网设备的80,569,070次交互。因此,我们获得了关键的物联网恶意软件情报,其中包括系统命令,无文件攻击证据,有效载荷URL,可执行和可链接格式(ELF)二进制文件,登录凭据,恶意LDAP服务器,以及对最近Log4shell安全漏洞滥用的独特见解。
The chronic proliferation of Internet of Things (IoT) botnet malware activities coupled with an unprecedented rise in security vulnerabilities convene a new world of opportunities for perpetrators and unveil a new set of hurdles in deriving relevant IoT malware intelligence. Such shortfall within the IoT paradigm exacerbates the capabilities for largely identifying the prevailing IoT malware threats, the origin of the IoT attacks, as well as, the security deficit associated with the IoT paradigm. Previous work has vastly studied IoT malware activities in the wild but has not profiled at a large scale malicious activities to collect in near real-time central IoT artifacts much-needed to understand and eventually elevate the security posture of the IoT ecosystem. To this end, we propose in this work a near real-time collection scheme to collect and analyze at large IoT malware artifacts essential for understanding the prevalent cyber security risks. We leverage in this work a large network telescope comprising of 16.7 million IPs as one extensive honeypot to examine evidence of malicious IoT probes in the wild. Subsequently, we employ a deception technique to respond to these probes and eventually establish bogus connections to collect IoT malware artifacts. In only 120 hours of near real-time measurements, our proposed scheme collected 80,569,070 interactions originating from 30,190 malware-infected IoT devices. Accordingly, we derive pivotal IoT malware intelligence which includes system commands, file-less attacks evidence, payload URLs, Executable and Linkable Format (ELF) binaries, log-in credentials, malicious LDAP servers, and unique insights on the abuse of the recent Log4shell security vulnerability in distributing IoT malware binaries.