Data-driven Curation, Learning and Analysis for Inferring Evolving IoT Botnets in the Wild

Data-driven Curation, Learning and Analysis for Inferring Evolving IoT Botnets in the Wild
复制标题

DOI:
10.1145/3339252.3339272
复制
发表时间:
2019-08
期刊:
Proceedings of the 14th International Conference on Availability, Reliability and Security
影响因子:
--
通讯作者:
Morteza Safaei Pour;Antonio Mangino;Kurt Friday;Matthias Rathbun;E. Bou-Harb;Farkhund Iqbal;K. Shaban;A. Erradi
Morteza Safaei Pour;Antonio Mangino;Kurt Friday;Matthias Rathbun;E. Bou-Harb;Farkhund Iqbal;K. Shaban;A. Erradi
中科院分区:
其他
文献类型:
--
作者:
Morteza Safaei Pour;Antonio Mangino;Kurt Friday;Matthias Rathbun;E. Bou-Harb;Farkhund Iqbal;K. Shaban;A. Erradi

文献摘要

相似文献

物联网(IoT)模式的不安全性继续在消费者和关键基础设施领域造成严重破坏。一些挑战阻碍了解决物联网安全问题,包括缺乏以物联网为中心的数据,这些数据可以收集、分析和关联,这是由于此类设备的高度异构性质及其在互联网环境中的广泛部署。为此,本文探讨了宏观的、被动的经验数据,以阐明这一不断演变的威胁现象。这不仅旨在通过单独观察这种单向网络流量来分类和推断互联网规模的受损物联网设备,而且还努力发现,跟踪和报告精心策划的“野外”物联网僵尸网络。首先,为了准备有效利用这些数据,设计并开发了一种新的概率模型来从噪声样本(即错误配置流量)中清除此类流量。随后,评估了几种浅层和深度学习模型,最终设计和开发了一个多窗口卷积神经网络,该网络经过主动和被动测量的训练,以准确识别受损的物联网设备。因此,为了推断由协调良好的物联网僵尸网络产生的精心策划和未经请求的活动,通过仔细检查一组创新和高效的网络功能集来部署分层聚合聚类。通过分析最近3.6 TB的暗网流量,该方法发现了44万个受损的物联网设备,并生成了与350个物联网僵尸网络相关的基于证据的工件。虽然这些检测到的僵尸网络中的一些指的是以前记录的活动,如Hide and Seek, Hajime和Fbot,但其他事件说明了不断发展的威胁,例如具有加密劫持能力的威胁以及针对工业控制系统通信和控制服务的威胁。
The insecurity of the Internet-of-Things (IoT) paradigm continues to wreak havoc in consumer and critical infrastructure realms. Several challenges impede addressing IoT security at large, including, the lack of IoT-centric data that can be collected, analyzed and correlated, due to the highly heterogeneous nature of such devices and their widespread deployments in Internet-wide environments. To this end, this paper explores macroscopic, passive empirical data to shed light on this evolving threat phenomena. This not only aims at classifying and inferring Internet-scale compromised IoT devices by solely observing such one-way network traffic, but also endeavors to uncover, track and report on orchestrated "in the wild" IoT botnets. Initially, to prepare the effective utilization of such data, a novel probabilistic model is designed and developed to cleanse such traffic from noise samples (i.e., misconfiguration traffic). Subsequently, several shallow and deep learning models are evaluated to ultimately design and develop a multi-window convolution neural network trained on active and passive measurements to accurately identify compromised IoT devices. Consequently, to infer orchestrated and unsolicited activities that have been generated by well-coordinated IoT botnets, hierarchical agglomerative clustering is deployed by scrutinizing a set of innovative and efficient network feature sets. By analyzing 3.6 TB of recent darknet traffic, the proposed approach uncovers a momentous 440,000 compromised IoT devices and generates evidence-based artifacts related to 350 IoT botnets. While some of these detected botnets refer to previously documented campaigns such as the Hide and Seek, Hajime and Fbot, other events illustrate evolving threats such as those with cryptojacking capabilities and those that are targeting industrial control system communication and control services.