Conficker and beyond: a large-scale empirical study

Conficker and beyond: a large-scale empirical study
复制标题

Conficker 及其他:大规模实证研究

DOI:
--
复制
发表时间:
2010
期刊:
Asia-Pacific Computer Systems Architecture Conference
影响因子:
--
通讯作者:
G. Gu
G. Gu
中科院分区:
--
文献类型:
--
作者:
Seungwon Shin;G. Gu

文献摘要

被引文献

相似文献

Conficker [26] 是最近最广泛传播、众所周知的蠕虫/机器人。据多份报告[16, 28],它已经感染了大约700万到1500万台主机,而且至今受害者仍在增加。在本文中,我们大规模分析了 Conficker 感染,包括约 2500 万受害者,并研究了有关这种最先进恶意软件的各种有趣的方面。通过分析Conficker,我们打算了解恶意软件传播的当前和新趋势,这对于预测未来的恶意软件趋势并为未来的恶意软件防御提供见解非常有帮助。我们观察到,与许多上一代蠕虫/僵尸网络相比,Conficker 具有一些非常不同的受害者分布模式,这表明可能需要新的恶意软件传播模型和防御策略。此外,我们打算确定基于信誉的黑名单方法在面对新的恶意软件威胁(例如 Conficker)时的表现如何。我们交叉检查了来自 Dshield [6] 和 FIRE [7] 的多个 DNS 黑名单和 IP/AS 信誉数据,我们的评估表明,与之前的研究 [18] 不同,该研究显示基于黑名单的方法可以检测大多数机器人,这些基于信誉的方法对于 Conficker 的效果相对较差。这就提出了一个问题,我们如何改进和补充现有的基于声誉的技术,为未来的恶意软件防御做好准备?最后,我们研究了一些针对防守者的见解。我们证明,在 Conficker 案例中,邻里监视是一种令人惊讶的有效方法。这表明安全警报共享/关联(特别是在邻近网络之间)可能是一种有前途的方法,并且在未来的恶意软件防御中发挥更重要的作用。
Conficker [26] is the most recent widespread, well-known worm/bot. According to several reports [16, 28], it has infected about 7 million to 15 million hosts and the victims are still increasing even now. In this paper, we analyze Conficker infections at a large scale, including about 25 millions victims, and study various interesting aspects about this state-of-the-art malware. By analyzing Conficker, we intend to understand current and new trends in malware propagation, which could be very helpful in predicting future malware trends and providing insights for future malware defense. We observe that Conficker has some very different victim distribution patterns compared to many previous generation worms/botnets, suggesting that new malware spreading models and defense strategies are likely needed. Furthermore, we intend to determine how well a reputation-based blacklisting approach can perform when faced with new malware threats such as Conficker. We cross-check several DNS blacklists and IP/AS reputation data from Dshield [6] and FIRE [7], and our evaluation shows that unlike a previous study [18] which shows that a blacklist-based approach can detect most bots, these reputation-based approaches did relatively poorly for Conficker. This raised the question, how can we improve and complement existing reputation-based techniques to prepare for future malware defense? Finally, we look into some insights for defenders. We show that neighborhood watch is a surprisingly effective approach in the Conficker case. This suggests that security alert sharing/correlation (particularly among neighborhood networks) could be a promising approach and play a more important role for future malware defense.