Understanding and Securing Device Vulnerabilities through Automated Bug Report Analysis

Understanding and Securing Device Vulnerabilities through Automated Bug Report Analysis
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Xuan Feng;Xiaojing Liao;Xiaofeng Wang;Haining Wang;Qiang Li;Kai-Ts'ung Yang;Hongsong Zhu;Limin Sun
Xuan Feng;Xiaojing Liao;Xiaofeng Wang;Haining Wang;Qiang Li;Kai-Ts'ung Yang;Hongsong Zhu;Limin Sun
中科院分区:
其他
文献类型:
--
作者:
Xuan Feng;Xiaojing Liao;Xiaofeng Wang;Haining Wang;Qiang Li;Kai-Ts'ung Yang;Hongsong Zhu;Limin Sun

文献摘要

被引文献

相似文献

近年来,基于物联网(IoT)的网络攻击有所增加。正如预期的那样,这些攻击是通过利用已知的安全漏洞从受损的物联网设备发起的。然而,不太清楚的是物联网设备漏洞普遍存在的根本原因及其安全影响,特别是它们如何影响正在进行的网络犯罪。为了更好地了解问题并寻求有效的方法来抑制基于物联网的攻击浪潮,我们根据从蜜罐收集的大量真实攻击痕迹,从地下购买的攻击工具以及从高配置物联网攻击中收集的信息进行了全面的研究。这项研究揭示了当今物联网系统的设备漏洞及其安全影响:正在进行的网络攻击严重依赖于这些已知漏洞和通过其报告发布的攻击代码;另一方面,这种对已知漏洞的依赖实际上可以用来对付对手。能够以极低成本开发攻击的相同错误报告也可以用来提取有助于阻止攻击的特定于可扩展性的功能。特别是,我们利用自然语言处理(NLP)自动收集和分析分布在互联网上的bug报告博客、论坛和邮件列表中的7,500多份安全报告(总共有12,286份安全关键物联网报告)。我们表明,签名可以通过一个基于NLP的报告自动生成
Recent years have witnessed the rise of Internet-of-Things (IoT) based cyber attacks. These attacks, as expected, are launched from compromised IoT devices by exploiting security flaws already known. Less clear, however, are the fundamental causes of the pervasiveness of IoT device vulnerabilities and their security implications, particularly in how they affect ongoing cybercrimes. To better understand the problems and seek effective means to suppress the wave of IoT-based attacks, we conduct a comprehensive study based on a large number of real-world attack traces collected from our honeypots, attack tools purchased from the underground, and information collected from high-profile IoT attacks. This study sheds new light on the device vulnerabilities of today’s IoT systems and their security implications: ongoing cyber attacks heavily rely on these known vulnerabilities and the attack code released through their reports; on the other hand, such a reliance on known vulnerabilities can actually be used against adversaries. The same bug reports that enable the development of an attack at an exceedingly low cost can also be leveraged to extract vulnerability-specific features that help stop the attack. In particular, we leverage Natural Language Processing (NLP) to automatically collect and analyze more than 7,500 security reports (with 12,286 security critical IoT flaws in total) scattered across bug-reporting blogs, forums, and mailing lists on the Internet. We show that signatures can be automatically generated through an NLP-based report