Paint It Black: Evaluating the Effectiveness of Malware Blacklists

Paint It Black: Evaluating the Effectiveness of Malware Blacklists
复制标题

DOI:
10.1007/978-3-319-11379-1_1
复制
发表时间:
2014-09
期刊:
--
影响因子:
--
通讯作者:
Marc Kührer;C. Rossow;Thorsten Holz
Marc Kührer;C. Rossow;Thorsten Holz
中科院分区:
其他
文献类型:
--
作者:
Marc Kührer;C. Rossow;Thorsten Holz

文献摘要

被引文献

相似文献

黑名单通常用于保护计算机系统免受大量恶意软件威胁。这些列表包括滥用主机,如恶意软件网站或僵尸网络命令与控制和dropzone服务器,以提高警报,如果可疑主机的联系。然而,到目前为止,人们对恶意软件黑名单的有效性知之甚少。在本文中,我们实证分析了15个公共恶意软件黑名单和4个反病毒(AV)供应商的黑名单。我们的目标是对黑名单内容进行分类,以了解所列域名和IP地址的性质。首先,我们提出了一种机制,以确定停放在黑名单中的域名,我们发现,构成了大量的黑名单条目。其次,我们开发了一种基于图的方法来识别黑名单中的漏洞,即,托管由安全组织控制的恶意域的服务器。在黑名单有效性的全面评估中,我们展示了黑名单在多大程度上覆盖了真实世界的恶意软件域。我们发现,工会的所有15个公共黑名单包括不到20%的恶意域名的大多数流行的恶意软件家族和大多数反病毒供应商黑名单无法防止恶意软件,利用域生成算法。
Blacklistsare commonly used to protect computer systems against the tremendous number of malware threats. These lists include abusive hosts such as malware sites or botnet Command & Control and dropzone servers to raise alerts if suspicious hosts are contacted. Up to now, though, little is known about theeffectivenessof malware blacklists.In this paper, we empirically analyze 15 public malware blacklists and 4 blacklists operated by antivirus (AV) vendors. We aim to categorize the blacklist content to understand the nature of the listed domains and IP addresses. First, we propose a mechanism to identify parked domains in blacklists, which we find to constitute a substantial number of blacklist entries. Second, we develop a graph-based approach to identify sinkholes in the blacklists, i.e., servers that host malicious domains which are controlled by security organizations. In a thorough evaluation of blacklist effectiveness, we show to what extent real-world malware domains are actually covered by blacklists. We find that the union of all 15 public blacklists includes less than 20% of the malicious domains for a majority of prevalent malware families and most AV vendor blacklists fail to protect against malware that utilizesDomain Generation Algorithms.