A First Step towards Live Botmaster Traceback

A First Step towards Live Botmaster Traceback
复制标题

DOI:
10.1007/978-3-540-87403-4_4
复制
发表时间:
2008-09
期刊:
--
影响因子:
--
通讯作者:
Daniel Ramsbrock;Xinyuan Wang;Xuxian Jiang
Daniel Ramsbrock;Xinyuan Wang;Xuxian Jiang
中科院分区:
其他
文献类型:
--
作者:
Daniel Ramsbrock;Xinyuan Wang;Xuxian Jiang

文献摘要

被引文献

相似文献

尽管僵尸网络威胁日益增加,但僵尸主机追踪领域的研究仍然有限。四个主要障碍是 1) bot 到 botmaster 链接的低流量性质; 2)“踏脚石”链条; 3) 在这些链上使用加密; 4) 与其他机器人的流量混合。大多数现有的回溯方法可以解决其中一两个问题,但没有一种方法可以克服所有这些问题。我们提出了一种新颖的流水印技术来同时解决所有四个障碍。我们的方法使我们能够唯一地识别和跟踪任何基于 IRC 的僵尸网络流,即使 1) 它是加密的(例如,通过 SSL/TLS); 2)它通过多个中间垫脚石(例如IRC服务器、SOCK); 3) 它与其他僵尸网络流量混合。我们的水印方案依赖于在应用层向传出僵尸网络 C&C 消息添加填充字符。这会在网络流中随机选择的消息对之间产生特定的长度差异。因此,我们的水印技术可用于跟踪任何交互式僵尸网络 C&C 流量,并且只需要几十个数据包即可生效。据我们所知,这是第一个有潜力允许在互联网上进行实时僵尸主机追踪的方法。我们通过在不同大陆的 PlanetLab 节点和公共 IRC 服务器上进行的现场实验,实证验证了僵尸网络流水印方法的有效性。我们几乎实现了水印(加密和未加密)IRC 流量的 100% 检测率,误报率约为 10− 5。由于 IRC 服务器的消息队列和节流功能,将箔条与水印流混合不会显着影响我们水印方法的有效性。
Despite the increasing botnet threat, research in the area of botmaster traceback is limited. The four main obstacles are 1) the low-traffic nature of the bot-to-botmaster link; 2) chains of “stepping stones;” 3) the use of encryption along these chains; and 4) mixing with traffic from other bots. Most existing traceback approaches can address one or two of these issues, but no single approach can overcome all of them. We present a novel flow watermarking technique to address all four obstacles simultaneously. Our approach allows us to uniquely identify and trace any IRC-based botnet flow even if 1) it is encrypted (e.g., via SSL/TLS); 2) it passes multiple intermediate stepping stones (e.g., IRC server, SOCKs); and 3) it is mixed with other botnet traffic. Our watermarking scheme relies on adding padding characters to outgoing botnet C&C messages at the application layer. This produces specific differences in lengths between randomly chosen pairs of messages in a network flow. As a result, our watermarking technique can be used to trace any interactive botnet C&C traffic and it only requires a few dozen packets to be effective. To the best of our knowledge, this is the first approach that has the potential to allow real-time botmaster traceback across the Internet.We have empirically validated the effectiveness of our botnet flow watermarking approach with live experiments on PlanetLab nodes and public IRC servers on different continents. We achieved virtually a 100% detection rate of watermarked (encrypted and unencrypted) IRC traffic with a false positive rate on the order of 10− 5. Due to the message queuing and throttling functionality of IRC servers, mixing chaff with the watermarked flow does not significantly impact the effectiveness of our watermarking approach.