FIRE: FInding Rogue nEtworks

FIRE: FInding Rogue nEtworks
复制标题

FIRE:寻找流氓网络

DOI:
10.1109/acsac.2009.29
复制
发表时间:
2009
期刊:
2009 Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
E. Kirda
E. Kirda
中科院分区:
--
文献类型:
--
作者:
Brett Stone;Christopher Krügel;K. Almeroth;Andreas Moser;E. Kirda

文献摘要

被引文献

相似文献

多年来,网络犯罪分子一直能够伪装在信誉不佳的互联网服务提供商(isp)背后进行非法活动。例如,俄罗斯商业网络(RBN)、Atrivo(又名Intercage)、McColo等组织,以及最近的三光纤网络(3FN),都没有受到惩罚,为互联网犯罪分子提供了一个安全的避风港,以获取他们自己的经济利益。这些互联网服务提供商与其他互联网服务提供商的主要区别在于其网络上恶意活动的显著持久性,以及对滥用报告明显缺乏反应。有趣的是,尽管互联网提供了一定程度的匿名性,但这些互联网服务提供商害怕公众的关注。一旦暴露,流氓网络通常会迅速停止其恶意活动,或者被上游提供商断开(断开)。因此,网络犯罪分子被迫转移他们的业务。在本文中,我们提出了FIRE,这是一种新的系统,用于识别和暴露表现出持续恶意行为的组织和isp。其目标是将一贯涉及恶意活动的网络与受到攻击的网络隔离开来。为此,FIRE积极监控僵尸网络通信通道、下载服务器和钓鱼网站。这些数据经过细化和关联,以量化各个组织的恶意活动程度。我们通过maliciousnetworks.org网站实时展示我们的结果。这些结果可用于查明和跟踪流氓组织的活动,防止犯罪分子在互联网上建立据点。此外,这些信息可以被编译成一个空路由黑名单,以立即阻止来自恶意网络的流量。
For many years, online criminals have been able to conduct their illicit activities by masquerading behind disreputable Internet Service Providers (ISPs). For example, organizations such as the Russian Business Network (RBN), Atrivo (a.k.a., Intercage), McColo, and most recently, the Triple Fiber Network (3FN) operated with impunity, providing a safe haven for Internet criminals for their own financial gain. What primarily sets these ISPs apart from others is the significant longevity of the malicious activities on their networks and the apparent lack of action taken in response to abuse reports. Interestingly, even though the Internet provides a certain degree of anonymity, such ISPs fear public attention. Once exposed, rogue networks often cease their malicious activities quickly, or are de-peered (disconnected) by their upstream providers. As a result, the Internet criminals are forced to relocate their operations. In this paper, we present FIRE, a novel system to identify and expose organizations and ISPs that demonstrate persistent, malicious behavior. The goal is to isolate the networks that are consistently implicated in malicious activity from those that are victims of compromise. To this end, FIRE actively monitors botnet communication channels, drive-by-download servers, and phishing web sites. This data is refined and correlated to quantify the degree of malicious activity for individual organizations. We present our results in real-time via the website maliciousnetworks.org. These results can be used to pinpoint and to track the activity of rogue organizations, preventing criminals from establishing strongholds on the Internet. Also, the information can be compiled into a null-routing blacklist to immediately halt traffic from malicious networks.