Fluxing botnet command and control channels with URL shortening services

被引:8
作者
Lee, Sangho [1 ]
Kim, Jong [2 ]
机构
[1] Pohang Univ Sci & Technol POSTECH, Dept Comp Sci & Engn, Pohang, South Korea
[2] Pohang Univ Sci & Technol POSTECH, Div IT Convergence Engn, Pohang, South Korea
基金
新加坡国家研究基金会;
关键词
Botnet; DNS; Domain flux; URL shortening service;
D O I
10.1016/j.comcom.2012.10.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
URL shortening services (USSes), which provide short aliases to registered long URLs, have become popular owing to Twitter. Despite their popularity, researchers do not carefully consider their security problems. in this paper, we explore botnet models based on USSes to prepare for new security threats before they evolve. Specifically, we consider using USSes for alias flux to hide botnet command and control (C&C) channels. In alias flux, a botmaster obfuscates the IP addresses of his C&C servers, encodes them as URLs, and then registers them to USSes with custom aliases generated by an alias generation algorithm. Later, each bot obtains the encoded IP addresses by contacting USSes using the same algorithm. For USSes that do not support custom aliases, the botmaster can use shared alias lists instead of the shared algorithm. DNS-based botnet detection schemes cannot detect an alias flux botnet, and network-level detection and blacklisting of the fluxed aliases are difficult. We also discuss possible countermeasures to cope with these new threats and investigate operating USSes. (C) 2012 Elsevier B.V. All rights reserved.
引用
收藏
页码:320 / 332
页数:13
相关论文
共 52 条
[1]  
[Anonymous], USENIX WORKSH LARG S
[2]  
[Anonymous], 2007, KNOW YOUR EN FAST FL
[3]  
[Anonymous], 1987, DOMAIN NAMES CONCEPT
[4]  
Antonakakis M, 2010, USENIX SEC S
[5]  
Antoniades D., 2011, INT WORLD WID WEB C
[6]  
Bilge L, 2011, NETW DISTR SYST SEC
[7]  
Caglayan A., 2010, HAW INT C SYST SCI H
[8]  
Canali D., 2011, INT WORLD WID WEB C
[9]  
Chen X., 2008, IEEE INT C DEP SYST
[10]   Identifying botnets by capturing group activities in DNS traffic [J].
Choi, Hyunsang ;
Lee, Heejo .
COMPUTER NETWORKS, 2012, 56 (01) :20-33