On data-driven curation, learning, and analysis for inferring evolving internet-of-Things (IoT) botnets in the wild

On data-driven curation, learning, and analysis for inferring evolving internet-of-Things (IoT) botnets in the wild
复制标题

DOI:
10.1016/j.cose.2019.101707
复制
发表时间:
2020-04
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Morteza Safaei Pour;Antonio Mangino;Kurt Friday;Matthias Rathbun;E. Bou-Harb;Farkhund Iqbal;Sagar Samtani;J. Crichigno;N. Ghani
Morteza Safaei Pour;Antonio Mangino;Kurt Friday;Matthias Rathbun;E. Bou-Harb;Farkhund Iqbal;Sagar Samtani;J. Crichigno;N. Ghani
中科院分区:
其他
文献类型:
--
作者:
Morteza Safaei Pour;Antonio Mangino;Kurt Friday;Matthias Rathbun;E. Bou-Harb;Farkhund Iqbal;Sagar Samtani;J. Crichigno;N. Ghani

文献摘要

被引文献

相似文献

物联网(IoT)模式的不安全性继续对消费者和关键基础设施造成严重破坏。物联网设备的高度异构性及其广泛部署导致了几个关键的安全和基于测量的挑战的出现,严重削弱了收集,分析和关联以物联网为中心的数据的过程。为此,本文探讨了宏观的,被动的经验数据,以揭示这种不断变化的威胁现象。拟议的工作旨在通过仅观察单向网络流量来分类和推断互联网规模的受损物联网设备,同时还发现,报告和彻底分析“野生”物联网僵尸网络。为了准备相关数据集,开发了一种新的概率模型,以通过去除噪声样本来净化不相关的流量(即,错误配置的网络流量)。随后,评估了几个浅层和深度学习模型,以训练有效的多窗口卷积神经网络。通过在生成训练数据集时利用主动和传递测量,神经网络旨在准确识别受损的物联网设备。因此,为了推断由协调良好的物联网僵尸网络生成的精心策划和未经请求的活动,通过仔细检查一组创新和高效的网络特征集来采用分层聚合聚类。分析最近捕获的3.6 TB暗网流量,发现有44万台受感染的物联网设备,并生成了与350个物联网僵尸网络相关的基于证据的工件。此外,通过对这些推断的活动进行深入分析,我们揭示了它们的扫描行为,数据包到达间隔时间,就业率和地理分布。虽然几个活动在这些方面表现出显着的差异,但有些活动更容易区分;通过限制在特定的地理位置或通过在其核心目标之外的随机端口上执行扫描。虽然许多推断的僵尸网络属于以前记录的活动,如Hide and Seek,HajimeandFbot,但新发现的事件通过展示不断增长的加密劫持能力或针对工业控制服务来描绘这种物联网威胁现象的演变性质。为了激励经验性(和操作性)物联网网络安全计划以及帮助获得结果的可重复性,我们将所有开发的方法和技术的源代码提供给整个研究社区。
The insecurity of the Internet-of-Things (IoT) paradigm continues to wreak havoc in consumer and critical infrastructures. The highly heterogeneous nature of IoT devices and their widespread deployments has led to the rise of several key security and measurement-based challenges, significantly crippling the process of collecting, analyzing and correlating IoT-centric data. To this end, this paper explores macroscopic, passive empirical data to shed light on this evolving threat phenomena. The proposed work aims to classify and infer Internet-scale compromised IoT devices by solely observing one-way network traffic, while also uncovering, reporting and thoroughly analyzing “in the wild” IoT botnets. To prepare a relevant dataset, a novel probabilistic model is developed to cleanse unrelated traffic by removing noise samples (i.e., misconfigured network traffic). Subsequently, several shallow and deep learning models are evaluated in an effort to train an effective multi-window convolutional neural network. By leveraging active and passing measurements when generating the training dataset, the neural network aims to accurately identify compromised IoT devices. Consequently, to infer orchestrated and unsolicited activities that have been generated by well-coordinated IoT botnets, hierarchical agglomerative clustering is employed by scrutinizing a set of innovative and efficient network feature sets. Analyzing 3.6 TB of recently captured darknet traffic revealed a momentous 440,000 compromised IoT devices and generated evidence-based artifacts related to 350 IoT botnets. Moreover, by conducting thorough analysis of such inferred campaigns, we reveal their scanning behaviors, packet inter-arrival times, employed rates and geo-distributions. Although several campaigns exhibit significant differences in these aspects, some are more distinguishable; by being limited to specific geo-locations or by executing scans on random ports besides their core targets. While many of the inferred botnets belong to previously documented campaigns such asHide and Seek,HajimeandFbot, newly discovered events portray the evolving nature of such IoT threat phenomena by demonstrating growing cryptojacking capabilities or by targeting industrial control services. To motivate empirical (and operational) IoT cyber security initiatives as well as aid in reproducibility of the obtained results, we make the source codes of all the developed methods and techniques available to the research community at large.