TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
TWC: Medium: Collaborative: Exposing and Mitigating Cross-Channel Attacks that Exploit the Convergence of Telephony and the Internet
批准号:
1514052
负责人:
Roberto Perdisci
金额:
$29.99万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-08-15 至 2021-07-31
中文摘要
技术的飞速发展使得人们可以随时随地使用智能手机同时接入电话和互联网服务。虽然电话与互联网的这种融合提供了许多好处,但它也为网络犯罪分子提供了开发越来越复杂的攻击的能力,这些攻击将电话和互联网渠道的资源结合起来。例如,含有互联网链接的短信可以将毫无戒心的用户引导到恶意网站,廉价或免费的语音服务可以用来进行电话诈骗活动,呼叫者id欺骗和自动拨号服务可以用来拨打电话,发动难以检测和追踪的大规模攻击。这种攻击通常在很长一段时间内未被发现,从而破坏了传统上与电话通道相关的更高级别的信任。本项目探索了一种基于事实的方法来研究和理解利用互联网和电话渠道的跨渠道攻击。关键目标是暴露跨通道攻击中使用的战术和基础设施与广泛观察和研究的仅限互联网的威胁之间的任何重叠。本研究使用了几个跨渠道滥用的数据来源,包括众包情报和电话蜜罐数据。目前可获得的许多电话滥用信息是非结构化的,其准确性或完整性尚不清楚。研究人员正在挖掘滥用信息的多种来源,并引入新的方法来更好地理解、检测和跟踪通过电话和互联网渠道进行的攻击。将这些渠道中可用的威胁情报相关联以提高两者的防御能力的有效性也进行了研究。通过研究促进跨通道攻击的恶意基础设施的特性,该项目将使研究人员和操作社区能够获得更多的态势感知,并开发减轻和防御这类新威胁的技术。
英文摘要
Rapid advances in technology now enable simultaneous access to both telephony and Internet services from smart phone devices that people carry with them at all times. Although this convergence of telephony with the Internet offers many benefits, it also provides cyber criminals the ability to develop increasingly sophisticated attacks that combine resources from both the telephony and Internet channels. For instance, text messages containing Internet links can direct unsuspecting users to malicious websites, inexpensive or free voice services can be used to carry out phone fraud campaigns, and caller-ID spoofing and autodialing services can be used to make calls to launch large-scale attacks that are difficult to detect and trace. Such attacks often remain undetected for long periods of time, thus undermining the higher level of trust that has traditionally been associated with the telephony channel.This project explores a ground-truth driven approach to study and understand cross-channel attacks that make use of both the Internet and telephony channels. A key goal is to expose any overlap in tactics and infrastructure used in cross-channel attacks with the extensively observed and studied Internet-only threats. Several data sources of cross-channel abuse are used in this study, including crowd-sourced intelligence and telephone-honeypot data. Much of the currently available telephony abuse information is unstructured and its accuracy or completeness is not known. The researchers are mining multiple sources of abuse information and introduce new methods to better understand, detect, and track attacks that are carried out across the telephony and Internet channels. The effectiveness of correlating threat intelligence available from each of these channels to improve defenses for both is also investigated. By studying the properties of the malicious infrastructure that facilitates cross-channel attacks, this project will enable both researchers and operational communities to gain increased situational awareness and develop techniques for mitigating and defending against this new class of threats.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Medium: Defending Against Social Engineering Attacks with In-Browser AI
-
批准号:2126641
-
项目类别:Standard Grant
-
资助金额:$40.0万
-
财政年份:2021
-
负责人:Roberto Perdisci
-
依托单位:
EAGER: Collaborative: Leveraging High-Density Internet Peering Hubs to Mitigate Large-Scale DDoS Attacks
-
批准号:1741608
-
项目类别:Standard Grant
-
资助金额:$17.98万
-
财政年份:2017
-
负责人:Roberto Perdisci
-
依托单位:
CAREER: Automatic Learning of Adaptive Network-Centric Malware Detection Models
-
批准号:1149051
-
项目类别:Continuing Grant
-
资助金额:$40.26万
-
财政年份:2012
-
负责人:Roberto Perdisci
-
依托单位:
SDCI Sec: Passive and Active DNS Monitoring Tools for Detecting and Tracking the Evolution of Malicious Domain Names
-
批准号:1127195
-
项目类别:Standard Grant
-
资助金额:$38.0万
-
财政年份:2011
-
负责人:Roberto Perdisci
-
依托单位:
海外基金