Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove Mirai

Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove Mirai
复制标题

清理互联网上的邪恶事物:关于 ISP 和消费者努力删除 Mirai 的真实证据

DOI:
10.14722/ndss.2019.23438
复制
发表时间:
2019
期刊:
Proceedings 2019 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
M. V. Eeten
M. V. Eeten
中科院分区:
--
文献类型:
--
作者:
Orçun Çetin;C. Gañán;L. Altena;Takahiro Kasama;D. Inoue;Kazuki Tamiya;Ying Tie;K. Yoshioka;M. V. Eeten

文献摘要

被引文献

相似文献

随着物联网僵尸网络的兴起,受感染设备的修复已成为一项关键任务。由于超过87%的这些设备驻留在宽带网络中,这项任务将主要落在消费者和互联网服务提供商身上。我们提出了物联网恶意软件清理的第一个实证研究-更具体地说,在中型ISP的网络中删除米拉伊感染。为了衡量补救率,我们结合了联合收割机的观察性研究和随机对照试验的数据,涉及220名遭受米拉伊感染的消费者,以及蜜罐和暗网的数据。我们发现,通过围墙花园来预防和通知受感染的客户,这是ISP僵尸网络缓解传统恶意软件的最佳实践,可以在14天内修复92%的感染。与未发送通知的对照组相比,仅发送电子邮件通知没有明显的影响。我们还测量了令人惊讶的高自然修复率为58-74%,这个对照组和两个参考网络,用户也没有得到通知。更令人惊讶的是,再感染率很低。在我们第一次研究后的五个月内,只有5%的补救客户再次感染。这与我们的实验室测试形成鲜明对比,实验室测试在几分钟内观察到真实的物联网设备的再感染-我们探索了各种不同的可能解释,但没有找到令人满意的答案。我们通过76次电话访谈和ISP的通信日志收集有关客户体验和行动的数据。即使许多用户从错误的心理模型操作,补救也会成功-例如,他们在PC上运行防病毒软件来解决物联网设备的感染问题。虽然清除受感染的设备显然非常有效,但未来的工作必须解决几个遗留的谜团。此外,由于互联网服务提供商的激励机制薄弱,很难扩大围墙花园解决方案的规模。
With the rise of IoT botnets, the remediation of infected devices has become a critical task. As over 87% of these devices reside in broadband networks, this task will fall primarily to consumers and the Internet Service Providers. We present the first empirical study of IoT malware cleanup in the wild -- more specifically, of removing Mirai infections in the network of a medium-sized ISP. To measure remediation rates, we combine data from an observational study and a randomized controlled trial involving 220 consumers who suffered a Mirai infection together with data from honeypots and darknets. We find that quarantining and notifying infected customers via a walled garden, a best practice from ISP botnet mitigation for conventional malware, remediates 92% of the infections within 14 days. Email-only notifications have no observable impact compared to a control group where no notifications were sent. We also measure surprisingly high natural remediation rates of 58-74% for this control group and for two reference networks where users were also not notified. Even more surprising, reinfection rates are low. Only 5% of the customers who remediated suffered another infection in the five months after our first study. This stands in contrast to our lab tests, which observed reinfection of real IoT devices within minutes -- a discrepancy for which we explore various different possible explanations, but find no satisfactory answer. We gather data on customer experiences and actions via 76 phone interviews and the communications logs of the ISP. Remediation succeeds even though many users are operating from the wrong mental model -- e.g., they run anti-virus software on their PC to solve the infection of an IoT device. While quarantining infected devices is clearly highly effective, future work will have to resolve several remaining mysteries. Furthermore, it will be hard to scale up the walled garden solution because of the weak incentives of the ISPs.