A Large-scale Analysis of Cloud Service Abuse
A Large-scale Analysis of Cloud Service Abuse
复制标题
云服务滥用的大规模分析
DOI:
--
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
M. Uchida
中科院分区:
文献类型:
--
作者:
Naoki Fukushi;Daiki Chiba;Mitsuaki Akiyama;M. Uchida
Cyber-attackers abuse cloud services as an infrastructure for their attacks. In a cloud service, the assigned Internet Protocol (IP) address for a server is owned by the cloud service provider. When the server is shut down, the assigned IP address is released and then assigned to another server in the same cloud service. Thus, cyber-attackers abusing cloud services pose a risk to legitimate service providers, developers, and end users of potentially being falsely blacklisted, which results in a poorer reputation for the service. In this study, we conducted a large-scale measurement of cloud service abuse using blacklisted IP addresses. Our analysis of four cloud services over 154 days using 39 blacklists revealed that a total of 61,060 IP addresses from these cloud service providers were blacklisted, approximately 14,000 IP addresses continue to be blacklisted, and approximately 5% are replaced daily. Moreover, our study revealed trends in attacks that abuse cloud services with respect to attack type, region, duration, and anti-abuse actions. Finally, we discussed recommendations for cloud service users, cloud service providers, and blacklist providers.
DOI:
10.14722/ndss.2018.23327
发表时间:
2018
期刊:
Internet Society Symposium on Network and Distributed System Security (NDSS
影响因子:
--
作者:
Borgolte, Kevin;Fiebig, Tobias;Hao, Shuang;Kruegel, Christopher;Vigna, Giovanni
通讯作者:
Vigna, Giovanni