A Systematic Characterization of IM Threats using Honeypots

A Systematic Characterization of IM Threats using Honeypots
复制标题

使用蜜罐对 IM 威胁进行系统表征

DOI:
--
复制
发表时间:
2010
期刊:
Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
S. Antonatos
S. Antonatos
中科院分区:
--
文献类型:
--
作者:
Iasonas Polakis;Thanasis Petsas;E. Markatos;S. Antonatos

文献摘要

被引文献

相似文献

即时消息(IM)服务的流行最近吸引了攻击者的兴趣,这些攻击者试图将恶意URL或文件发送到受损的即时消息帐户或客户端的联系人列表。这项工作的重点是一个系统的表征IM威胁的基础上收集的信息HoneyBuddy,蜜罐般的基础设施,用于检测IM网络中的恶意活动。HoneyBuddy通过查询流行的搜索引擎查找IM联系人或在联系人查找器网站上为其帐户做广告来查找联系人并将其添加到蜜罐信使。我们的部署表明,有超过6000个联系人,我们每天可以收集50到110个恶意URL以及可执行文件。我们的实验表明,我们收集的可执行样本中有21%没有被其他恶意软件收集基础设施收集,而93%的识别IM钓鱼域没有被流行的黑名单机制记录。此外,我们的研究结果表明,恶意域名由有限数量的主机托管,这些主机在整个时间内几乎保持不变。
The popularity of instant messaging (IM) services has recently attracted the interest of attackers that try to send malicious URLs or files to the contact lists of compromised instant messaging accounts or clients. This work focuses on a systematic characterization of IM threats based on the information collected by HoneyBuddy, a honeypot-like infrastructure for detecting malicious activities in IM networks. HoneyBuddy finds and adds contacts to its honeypot messengers by querying popular search engines for IM contacts or by advertising its accounts on contact finder sites. Our deployment has shown that with over six thousand contacts we can gather between 50 and 110 malicious URLs per day as well as executables. Our experiments show that 21% of our collected executable samples were not gathered by other malware collection infrastructures, while 93% of the identified IM phishing domains were not recorded by popular blacklist mechanisms. Furthermore, our findings show that the malicious domains are hosted by a limited number of hosts that remain practically unchanged throughout time.