Analysis of a "/0" Stealth Scan From a Botnet

Analysis of a "/0" Stealth Scan From a Botnet
复制标题

DOI:
10.1109/tnet.2013.2297678
复制
发表时间:
2015-04-01
影响因子:
3.7
通讯作者:
Pescape, Antonio
Pescape, Antonio
中科院分区:
计算机科学2区
文献类型:
--
作者:
Dainotti, Alberto;King, Alistair;Pescape, Antonio

文献摘要

被引文献

相似文献

僵尸网络是网络犯罪活动最常见的工具。它们被用于垃圾邮件、网络钓鱼、拒绝服务攻击、暴力破解、窃取私人信息和网络战争。僵尸网络进行网络扫描有几个原因,包括搜索易受攻击的机器来感染和招募到僵尸网络中,探测网络进行枚举或渗透等。我们展示了2011年2月saly僵尸网络对整个IPv4地址空间进行的水平扫描的测量和分析。这个为期12天的扫描源自大约300万个不同的IP地址,并使用高度协调和异常隐蔽的扫描策略来试图发现和破坏与voip相关的(SIP服务器)基础设施。我们通过UCSD网络望远镜观察到这一事件,a /8暗网持续接收大量未经请求的流量,我们将这些流量数据与其他公共数据来源相关联,以验证我们的推断。Sality是研究人员发现的最大的僵尸网络之一。它的行为代表了现代恶意软件发展的不祥进展:数百万协同机器人使用更复杂的隐形扫描策略,目标是关键的语音通信基础设施。本文提供了对僵尸网络扫描行为的详细剖析,包括在全球互联网上关联、可视化和推断僵尸网络行为的一般方法。
Botnets are the most common vehicle of cyber-criminal activity. They are used for spamming, phishing, denial-of-service attacks, brute-force cracking, stealing private information, and cyber warfare. Botnets carry out network scans for several reasons, including searching for vulnerable machines to infect and recruit into the botnet, probing networks for enumeration or penetration, etc. We present the measurement and analysis of a horizontal scan of the entire IPv4 address space conducted by the Sality botnet in February 2011. This 12-day scan originated from approximately 3 million distinct IP addresses and used a heavily coordinated and unusually covert scanning strategy to try to discover and compromise VoIP-related (SIP server) infrastructure. We observed this event through the UCSD Network Telescope, a /8 darknet continuously receiving large amounts of unsolicited traffic, and we correlate this traffic data with other public sources of data to validate our inferences. Sality is one of the largest botnets ever identified by researchers. Its behavior represents ominous advances in the evolution of modern malware: the use of more sophisticated stealth scanning strategies by millions of coordinated bots, targeting critical voice communications infrastructure. This paper offers a detailed dissection of the botnet's scanning behavior, including general methods to correlate, visualize, and extrapolate botnet behavior across the global Internet.