Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared Hosting

Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared Hosting
复制标题

聚集脆弱的猫:一种统计方法来消除共享托管中网络安全的共同责任

DOI:
10.1145/3133956.3133971
复制
发表时间:
2017
期刊:
Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
M. V. Eeten
M. V. Eeten
中科院分区:
--
文献类型:
--
作者:
Samaneh Tajalizadehkhoob;Tom van Goethem;Maciej Korczyński;Arman Noroozian;Rainer Böhme;T. Moore;W. Joosen;M. V. Eeten

文献摘要

被引文献

相似文献

主机托管提供商在打击网络入侵方面起着关键作用,但其防止滥用的能力受到其自身客户安全措施的限制。共享主机托管提供了一个独特的视角,因为客户在受限的权限下操作,而提供商对配置保留更多的控制权。我们首次对共享主机托管提供商中网络安全特性的分布和软件补丁措施、提供商对这些安全措施的影响以及它们对网络入侵率的影响进行了实证分析。我们通过从442,684个域名收集指标,构建了全球共享主机托管市场(包含1,259个提供商)的提供商层面的特性。对15个指标的探索性因素分析确定了四个主要的潜在因素,它们涵盖了安全工作:内容安全、网站管理员安全、网络基础设施安全和网络应用安全。我们通过固定效应回归模型证实,提供商对后两个因素有显著影响,这两个因素都与他们主机托管环境中的软件栈相关。最后,通过对网络钓鱼和恶意软件滥用这些因素进行广义线性模型回归分析,我们表明在控制规模之后,这四个安全和软件补丁因素解释了提供商处滥用行为10%到19%的方差。例如,对于网络应用安全,我们发现当一个提供商从表现最差的10%提升到表现最佳的10%时,其遭受的网络钓鱼事件会减少4倍。我们表明提供商对补丁级别有影响——在软件栈中甚至更高,在那里内容管理系统可以作为客户端软件运行——并且这种影响与滥用水平的大幅降低相关。
Hosting providers play a key role in fighting web compromise, but their ability to prevent abuse is constrained by the security practices of their own customers. Shared hosting, offers a unique perspective since customers operate under restricted privileges and providers retain more control over configurations. We present the first empirical analysis of the distribution of web security features and software patching practices in shared hosting providers, the influence of providers on these security practices, and their impact on web compromise rates. We construct provider-level features on the global market for shared hosting -- containing 1,259 providers -- by gathering indicators from 442,684 domains. Exploratory factor analysis of 15 indicators identifies four main latent factors that capture security efforts: content security, webmaster security, web infrastructure security and web application security. We confirm, via a fixed-effect regression model, that providers exert significant influence over the latter two factors, which are both related to the software stack in their hosting environment. Finally, by means of GLM regression analysis of these factors on phishing and malware abuse, we show that the four security and software patching factors explain between 10% and 19% of the variance in abuse at providers, after controlling for size. For web-application security for instance, we found that when a provider moves from the bottom 10% to the best-performing 10%, it would experience 4 times fewer phishing incidents. We show that providers have influence over patch levels--even higher in the stack, where CMSes can run as client-side software--and that this influence is tied to a substantial reduction in abuse levels.