Creating a Large-scale Memory Error IoT Botnet Using NS3DockerEmulator

Creating a Large-scale Memory Error IoT Botnet Using NS3DockerEmulator
复制标题

DOI:
10.1109/dsn58367.2023.00051
复制
发表时间:
2023-06
期刊:
2023 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Islam Obaidat;Bennett Kahn;Fatemeh Tavakoli;Meera Sridhar
Islam Obaidat;Bennett Kahn;Fatemeh Tavakoli;Meera Sridhar
中科院分区:
其他
文献类型:
--
作者:
Islam Obaidat;Bennett Kahn;Fatemeh Tavakoli;Meera Sridhar

文献摘要

相似文献

DDoSim是一个模拟真实世界的大规模僵尸网络DDoS攻击的仿真测试平台。DDoSim提供各种功能,包括运行用户指定的软件、测试僵尸网络招募漏洞以及测量导致的DDoS攻击的严重性。DDoSim利用NS 3DockerEmulator的Docker和NS-3集成来加载带有实际二进制文件的Docker容器,并通过模拟的NS-3网络连接它们。通过与真实的硬件实验结果的比较,验证了DDoSim的有效性。本文重点介绍了一系列关于在物联网设备上部署内存错误僵尸网络的实验结果。与依赖默认凭据的米拉伊攻击不同,这些实验利用内存错误漏洞访问物联网设备。DDoSim还实现了真实的物联网流失,反映了真实世界物联网环境中的动态网络条件。结果显示,内存错误漏洞使僵尸网络招募,而网络条件,攻击规模和持续时间都对目标服务器有成比例的影响。DDoSim可供研究人员公开使用。
DDoSim, a simulation testbed for mimicking real-world, large-scale botnet DDoS attacks, is presented. DDoSim offers various capabilities, including running user-specified software, testing botnet-recruitment exploits, and measuring the severity of resulting DDoS attacks. DDoSim leverages NS3DockerEmulator's Docker and NS-3 integration to load Docker containers with actual binaries and connect them over a simulated NS-3 network. DDoSim is validated through a comparison with results from real hardware experiments. This paper focuses on the results of an experiment series concerning deploying a memory error botnet on IoT devices. Unlike the Mirai attack, which relies on default credentials, these experiments exploit memory error vulnerabilities to access IoT devices. DDoSim also implements realistic IoT churn, reflecting dynamic network conditions in real-world IoT environments. The results reveal that memory error vulnerabilities enable botnet recruitment, while network conditions, attack size, and duration all have a proportional impact on target servers. DDoSim is publicly available for researchers' use.