C. Dörr
Please Note
23 records found
1
Although CTI has been developed and generated for the past decades many challenges remain to be solved. Most of the defense systems designed using CTI utilize simple indicators such as hash values and IP addresses, and are therefore easily circumvented by cybercriminals. In addition, the cyber landscape is in continuous motion, causing intelligence to become stale, and decreasing the effectiveness of related defense mechanisms. In this dissertation, we contribute to the state of the art by investigating whether it is possible to, in the early stages of attacks, extract information characterizing the criminal’s toolchain and identify behavioral traits. Generating CTI at the early stage of attacks provides the support for defending parties to develop a defense mechanism able to stop criminals in the early stage of attacks preventing them from causing further damage. We focus on gathering CTI related to the tools, tactics, techniques, and procedures attackers use, as they provide the valuable information for developing defense systems.
We observe that the scan landscape has significantly changed in the past nine years and that defense mechanisms based on low-value CTI provide insufficient protection. The observed changes and analyses confirm the necessity to continuously monitor the current threat landscape and adapt the defense mechanisms accordingly. Following, we propose a clustering-based methodology matching randomized scan probe payloads allowing for the reconstruction of templates used by attackers. Using reconstructed templates we can detect large-scale scanning campaigns, and the convergence of cybercriminals using similar toolchains over time increasing the difficulty of distinguishing between criminal operations. To differentiate similar toolchains we analyzed the fingerprinting of SSH handshakes and reveal that the libraries and their versions used to compile said toolchains can be identified allowing further differentiation between campaigns and thus the behavioral analysis of cybercriminals. We showcase that attackers employing distinct toolchains at the early attack stages will behave differently at later attack stages. Finally, we analyze Mirai brute-forcing attacks identifying the different botnet configurations cybercriminals use. We simulate competing botnets configured with the observed settings and conclude that the implemented changes improve the botnet's success rate, indicating that criminals are constantly refining their operations.
In summary, we contribute to the state of the art by generating CTI characterizing the tools, tactics, techniques, and procedures attackers use. The generated CTI spans multiple layers of the toolchains attackers use, providing actionable intelligence at the early attack stages. The generated intelligence can, therefore, contribute to the design of defense in depth systems aimed at mitigating cyberattacks. ...
Although CTI has been developed and generated for the past decades many challenges remain to be solved. Most of the defense systems designed using CTI utilize simple indicators such as hash values and IP addresses, and are therefore easily circumvented by cybercriminals. In addition, the cyber landscape is in continuous motion, causing intelligence to become stale, and decreasing the effectiveness of related defense mechanisms. In this dissertation, we contribute to the state of the art by investigating whether it is possible to, in the early stages of attacks, extract information characterizing the criminal’s toolchain and identify behavioral traits. Generating CTI at the early stage of attacks provides the support for defending parties to develop a defense mechanism able to stop criminals in the early stage of attacks preventing them from causing further damage. We focus on gathering CTI related to the tools, tactics, techniques, and procedures attackers use, as they provide the valuable information for developing defense systems.
We observe that the scan landscape has significantly changed in the past nine years and that defense mechanisms based on low-value CTI provide insufficient protection. The observed changes and analyses confirm the necessity to continuously monitor the current threat landscape and adapt the defense mechanisms accordingly. Following, we propose a clustering-based methodology matching randomized scan probe payloads allowing for the reconstruction of templates used by attackers. Using reconstructed templates we can detect large-scale scanning campaigns, and the convergence of cybercriminals using similar toolchains over time increasing the difficulty of distinguishing between criminal operations. To differentiate similar toolchains we analyzed the fingerprinting of SSH handshakes and reveal that the libraries and their versions used to compile said toolchains can be identified allowing further differentiation between campaigns and thus the behavioral analysis of cybercriminals. We showcase that attackers employing distinct toolchains at the early attack stages will behave differently at later attack stages. Finally, we analyze Mirai brute-forcing attacks identifying the different botnet configurations cybercriminals use. We simulate competing botnets configured with the observed settings and conclude that the implemented changes improve the botnet's success rate, indicating that criminals are constantly refining their operations.
In summary, we contribute to the state of the art by generating CTI characterizing the tools, tactics, techniques, and procedures attackers use. The generated CTI spans multiple layers of the toolchains attackers use, providing actionable intelligence at the early attack stages. The generated intelligence can, therefore, contribute to the design of defense in depth systems aimed at mitigating cyberattacks.
Opening Pandora’s Box
Charting the ecosystem of Command and Control infrastructures in a terabit-scale network
Clusus
A cyber range for network attack simulations
Inadvertently Making Cybercriminals Rich
A Comprehensive Study of Cryptojacking Campaigns at Internet Scale
In this thesis, we perform multiple large studies on cryptojacking to fill these gaps. After crawling a random sample of 49M domains, 20% of the Internet, we conclude that cryptojacking is present on 0.011% of all domains and that adult content is the most prevalent category of websites affected. We show that this percentage is significantly larger in the popular part of the Internet. This led to the conclusion that surveying solely domains listed in the Alexa Top 1M to estimate cryptojacking prevalence results in an overestimation of the problem. Furthermore, we show that infection rates on different Top Level Domains (TLDs) differ widely, as the Russian zone is home to a disproportionate number of cryptojacking domains, while other large TLDs -- such as .com -- show a significantly lower number of infections.
In another crawl, we have identified 204 cryptojacking campaigns on websites, an order of magnitude more than previous work, which indicates that the extent of these campaigns is heavily underestimated. The results of the two crawls combined reveal that 48% of all cryptojacking activity on websites is organized. The identified campaigns ranged in sizes from only 5 to 987 websites and we discovered that cybercriminals have chosen third-party software -- such as WordPress and Drupal -- as their method of choice for spreading cryptojacking infections efficiently. With a novel method of using NetFlow data recorded in a Tier 1 network, we estimated the popularity of mining applications, which showed that while Coinhive has a larger installed base, CoinImp WebSocket proxies were digesting significantly more traffic in the second half of 2018.
We have reported about a new attack vector that drastically overshadows all other cryptojacking activity. Through a firmware vulnerability in MikroTik routers, cybercriminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing Web connection. Thus, every Web page visited by any user behind an infected router would mine to profit the adversaries. Based on the aforementioned NetFlow data, weekly third-party crawls and network telescope traffic, we were able to follow their activities over a period of 10 months. We report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, which is approximately 70% of all MikroTik devices deployed in the world. During the peak of this attack, more than 440K routers were infected concurrently.
We have discovered that half of the infected routers are patched within 18 days after compromise, but 30% of the infections last longer than 50 days. Additionally, we observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. The combination of datasets allowed us to link tens of seemingly different infections to one actor.
Our analysis of cryptojacking with a focus on organized campaigns has shown that cybercriminals have successfully discovered a new method for monetary gain. With the discontinuation of Coinhive due to decreased Monero prices in March 2019, the cryptojacking landscape has changed enormously, and we are curious who will fill this power vacuum. As browser-based mining is not anywhere near as profitable as it was in early 2018, we believe that singular cryptojacking activity -- by individual website owners -- will decrease. However, we expect adversaries to find possibilities of deploying cryptojacking at an even larger scale to still be profitable. This stresses the importance of researching campaigns, as the reuse of techniques, tactics and procedures in deploying them provides an effective angle to detect and mitigate these malicious activities. With prices decreasing throughout 2018, one would expect that this problem will eventually solve itself. Apart from the discontinuation of Coinhive, there is no clear indication that this is the case, as Monero prices have started to recover in the first months of 2019. If this trend continues, we expect to experience another outbreak of large cryptojacking campaigns, as robust defenses are still not widely implemented. ...
In this thesis, we perform multiple large studies on cryptojacking to fill these gaps. After crawling a random sample of 49M domains, 20% of the Internet, we conclude that cryptojacking is present on 0.011% of all domains and that adult content is the most prevalent category of websites affected. We show that this percentage is significantly larger in the popular part of the Internet. This led to the conclusion that surveying solely domains listed in the Alexa Top 1M to estimate cryptojacking prevalence results in an overestimation of the problem. Furthermore, we show that infection rates on different Top Level Domains (TLDs) differ widely, as the Russian zone is home to a disproportionate number of cryptojacking domains, while other large TLDs -- such as .com -- show a significantly lower number of infections.
In another crawl, we have identified 204 cryptojacking campaigns on websites, an order of magnitude more than previous work, which indicates that the extent of these campaigns is heavily underestimated. The results of the two crawls combined reveal that 48% of all cryptojacking activity on websites is organized. The identified campaigns ranged in sizes from only 5 to 987 websites and we discovered that cybercriminals have chosen third-party software -- such as WordPress and Drupal -- as their method of choice for spreading cryptojacking infections efficiently. With a novel method of using NetFlow data recorded in a Tier 1 network, we estimated the popularity of mining applications, which showed that while Coinhive has a larger installed base, CoinImp WebSocket proxies were digesting significantly more traffic in the second half of 2018.
We have reported about a new attack vector that drastically overshadows all other cryptojacking activity. Through a firmware vulnerability in MikroTik routers, cybercriminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing Web connection. Thus, every Web page visited by any user behind an infected router would mine to profit the adversaries. Based on the aforementioned NetFlow data, weekly third-party crawls and network telescope traffic, we were able to follow their activities over a period of 10 months. We report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, which is approximately 70% of all MikroTik devices deployed in the world. During the peak of this attack, more than 440K routers were infected concurrently.
We have discovered that half of the infected routers are patched within 18 days after compromise, but 30% of the infections last longer than 50 days. Additionally, we observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. The combination of datasets allowed us to link tens of seemingly different infections to one actor.
Our analysis of cryptojacking with a focus on organized campaigns has shown that cybercriminals have successfully discovered a new method for monetary gain. With the discontinuation of Coinhive due to decreased Monero prices in March 2019, the cryptojacking landscape has changed enormously, and we are curious who will fill this power vacuum. As browser-based mining is not anywhere near as profitable as it was in early 2018, we believe that singular cryptojacking activity -- by individual website owners -- will decrease. However, we expect adversaries to find possibilities of deploying cryptojacking at an even larger scale to still be profitable. This stresses the importance of researching campaigns, as the reuse of techniques, tactics and procedures in deploying them provides an effective angle to detect and mitigate these malicious activities. With prices decreasing throughout 2018, one would expect that this problem will eventually solve itself. Apart from the discontinuation of Coinhive, there is no clear indication that this is the case, as Monero prices have started to recover in the first months of 2019. If this trend continues, we expect to experience another outbreak of large cryptojacking campaigns, as robust defenses are still not widely implemented.
Android App Tracking
Investigating the feasibility of tracking user behavior on mobile phones by analyzing encrypted network traffic
Detecting BGP Origin Hijacks
Using a filter-based approach
In this paper, we describe various strategies on how a distributed port scan is performed by adversaries in the wild. The results in this paper are found by analyzing network packets that stem from a large network telescope.
Concretely, we analyzed network traffic from one month received by 2 /16 networks. From this analysis, we conclude that many levels of coordination are exhibited by adversaries performing distributed port scans. ...
In this paper, we describe various strategies on how a distributed port scan is performed by adversaries in the wild. The results in this paper are found by analyzing network packets that stem from a large network telescope.
Concretely, we analyzed network traffic from one month received by 2 /16 networks. From this analysis, we conclude that many levels of coordination are exhibited by adversaries performing distributed port scans.
We introduce Honeytrack, a persistent scalable virtual high-interaction honeypot for the Internet of Things. Honeytrack aims to solve the limitations of the current available honeypots by providing the means to analyse adversaries in large networks. By using isolated containers for the high-interaction module, it allows for saving state for each adversary. In addition to that, the data collected by
Honeytrack allows for an in-depth analysis of every phase of an attack, going beyond the traditional malware-sample based research. By saving machine state, and binding this state to a certain attacker, we can serve attackers their “own” previously attacked honeypot, serving a large number of parallel adversaries at a time and allowing research into follow-up attacks. ...
We introduce Honeytrack, a persistent scalable virtual high-interaction honeypot for the Internet of Things. Honeytrack aims to solve the limitations of the current available honeypots by providing the means to analyse adversaries in large networks. By using isolated containers for the high-interaction module, it allows for saving state for each adversary. In addition to that, the data collected by
Honeytrack allows for an in-depth analysis of every phase of an attack, going beyond the traditional malware-sample based research. By saving machine state, and binding this state to a certain attacker, we can serve attackers their “own” previously attacked honeypot, serving a large number of parallel adversaries at a time and allowing research into follow-up attacks.
Extending Honeytrap with Lua scripting
Honeytrap LUA implementation
Threat Intelligence emerged as a valuable domain to enhance security defences by studying threats motives, techniques, tools and procedures. Campaign analysis is a process that belongs to this domain and deals with following attackers through time by linking several hack attempts that share a threat actor, a victim and that have a specific goal. Unfortunately, this process is rarely applied in practice because the campaign analysis models available in literature rely on manual investigation by security professionals. This approach can become quickly too expensive, both regarding time and human resources.
In this thesis project, we improve the state of the art by automating a popular campaign analysis framework introduced in 2011 by Lockheed Martin security researchers Hutchins et al. We do not only automate the process: we also improve its recall performance to provide security analyst with more interesting and complete findings. Hopefully, this will empower all organisations, of any size an security profile, to perform their threat intelligence. Lowering the adoption threshold is a fundamental requirement that is inescapable if we want security to improve horizontally throughout all industry sectors. Widespread adoption of campaign analysis would lead to a broader and quicker understanding of threat campaigns and goals, contributing to a safer society. ...
Threat Intelligence emerged as a valuable domain to enhance security defences by studying threats motives, techniques, tools and procedures. Campaign analysis is a process that belongs to this domain and deals with following attackers through time by linking several hack attempts that share a threat actor, a victim and that have a specific goal. Unfortunately, this process is rarely applied in practice because the campaign analysis models available in literature rely on manual investigation by security professionals. This approach can become quickly too expensive, both regarding time and human resources.
In this thesis project, we improve the state of the art by automating a popular campaign analysis framework introduced in 2011 by Lockheed Martin security researchers Hutchins et al. We do not only automate the process: we also improve its recall performance to provide security analyst with more interesting and complete findings. Hopefully, this will empower all organisations, of any size an security profile, to perform their threat intelligence. Lowering the adoption threshold is a fundamental requirement that is inescapable if we want security to improve horizontally throughout all industry sectors. Widespread adoption of campaign analysis would lead to a broader and quicker understanding of threat campaigns and goals, contributing to a safer society.
Popularity-based Detection of Domain Generation Algorithms
Or: How to detect botnets?
Today's detection mechanisms are evaluated for botnets that make the next obvious evolutionary step, and replace domain names generated from random letters with randomly selected, but actual dictionary words. It can be seen that the performance of state-of-the-art solutions that rely on linguistic feature detection would significantly decline after this transition, and an alternative novel approach to detect DGAs without making any assumptions on the internal structure and generating patterns of these algorithms is proposed. ...
Today's detection mechanisms are evaluated for botnets that make the next obvious evolutionary step, and replace domain names generated from random letters with randomly selected, but actual dictionary words. It can be seen that the performance of state-of-the-art solutions that rely on linguistic feature detection would significantly decline after this transition, and an alternative novel approach to detect DGAs without making any assumptions on the internal structure and generating patterns of these algorithms is proposed.