Cloud Watching: Understanding Attacks Against Cloud-Hosted Services

Cloud Watching: Understanding Attacks Against Cloud-Hosted Services
复制标题

DOI:
10.1145/3618257.3624818
复制
发表时间:
2023-09
期刊:
Proceedings of the 2023 ACM on Internet Measurement Conference
影响因子:
--
通讯作者:
Liz Izhikevich;M. Tran;Michalis Kallitsis;Aurore Fass;Zakir Durumeric
Liz Izhikevich;M. Tran;Michalis Kallitsis;Aurore Fass;Zakir Durumeric
中科院分区:
其他
文献类型:
--
作者:
Liz Izhikevich;M. Tran;Michalis Kallitsis;Aurore Fass;Zakir Durumeric

文献摘要

被引文献

相似文献

云计算极大地改变了服务部署模式。在这项工作中,我们分析了攻击者如何识别和定位云服务,与传统的企业网络和网络望远镜相比。使用5个提供商和23个国家的云蜜罐以及2个教育网络和1个网络望远镜,我们分析了IP地址分配,地理位置,网络和服务端口选择如何影响云中的目标服务。我们发现,针对云计算的扫描器是有选择性的:它们避免扫描没有合法服务的网络,并且它们区分地理区域。此外,攻击者挖掘互联网服务搜索引擎以找到可利用的服务,在某些情况下,他们避免针对IANA分配的协议,导致研究人员在选定端口上错误分类至少15%的流量。根据我们的研究结果,我们得出的建议,研究人员和运营商。
Cloud computing has dramatically changed service deployment patterns. In this work, we analyze how attackers identify and target cloud services in contrast to traditional enterprise networks and network telescopes. Using a diverse set of cloud honeypots in 5 providers and 23 countries as well as 2 educational networks and 1 network telescope, we analyze how IP address assignment, geography, network, and service-port selection, influence what services are targeted in the cloud. We find that scanners that target cloud compute are selective: they avoid scanning networks without legitimate services and they discriminate between geographic regions. Further, attackers mine Internet-service search engines to find exploitable services and, in some cases, they avoid targeting IANA-assigned protocols, causing researchers to misclassify at least 15% of traffic on select ports. Based on our results, we derive recommendations for researchers and operators.