Understanding and Detecting Remote Infection on Linux-based IoT Devices

Understanding and Detecting Remote Infection on Linux-based IoT Devices
复制标题

DOI:
10.1145/3488932.3517423
复制
发表时间:
2022-05
期刊:
Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Hongda Li;Qiqing Huang;Fei Ding;Hongxin Hu;Long Cheng;G. Gu;Ziming Zhao
Hongda Li;Qiqing Huang;Fei Ding;Hongxin Hu;Long Cheng;G. Gu;Ziming Zhao
中科院分区:
其他
文献类型:
--
作者:
Hongda Li;Qiqing Huang;Fei Ding;Hongxin Hu;Long Cheng;G. Gu;Ziming Zhao

文献摘要

被引文献

相似文献

激增的人口、糟糕的安全性和24/7的在线属性使得基于Linux的物联网(IoT)设备成为攻击者的理想目标。然而,由于预算限制和这些设备上的大量漏洞,保护它们免受攻击非常具有挑战性。因此,了解和检测物联网恶意软件远程感染,这是在受感染的物联网设备被对手货币化之前,对于减轻物联网恶意软件造成的损害和经济损失至关重要。在本文中,我们对从VirusShare收集的403,464个样本和大量物联网蜜罐的大规模数据集进行了实证研究,以深入了解物联网恶意软件远程感染的特征。我们分享了数据集中发现的shell命令的详细统计数据,突出了通过这些命令执行的恶意行为,调查了这些命令的指纹识别方法的当前状态,并通过引入感染能力的概念提供了shell命令的分类。为了证明从我们的研究中获得的知识的有用性,我们开发了一种方法来检测正在进行的远程感染活动的感染能力的基础上。我们的评估表明,我们的检测方法可以实现99.22%的远程感染在野外的检测率,并引入小的性能开销。
The rocketed population, poor security, and 24/7 online properties make Linux-based Internet of Things (IoT) devices ideal targets for attackers. However, due to the budget constraints and an enormous number of vulnerabilities on such devices, protecting them against attacks is very challenging. Therefore, understanding and detecting IoT malware remote infection, which is before the compromised IoT devices are monetized by adversaries, is crucial to mitigate damages and financial loss caused by IoT malware. In this paper, we conduct an empirical study on a large-scale dataset covering 403,464 samples collected from VirusShare and a large group of IoT honeypots to gain a deep insight into the characteristics of IoT malware remote infection. We share detailed statistics of shell commands found in our dataset, highlight malicious behaviors performed through those commands, investigate current states of fingerprinting methods of those commands, and offer a taxonomy of shell commands by introducing the notion of infection capability. To demonstrate the usefulness of the knowledge gained from our study, we develop an approach to detect ongoing remote infection activities based on infection capabilities. Our evaluation shows that our detection approach can achieve a 99.22% detection rate for remote infections in the wild and introduce small performance overhead.