Take A Deep Breath A Stealthy, Resilient And Cost-Effective Botnet Using Skype

DIMVA'10: Proceedings of the 7th international conference on Detection of intrusions and malware, and vulnerability assessment(2010)

引用 24|浏览51
暂无评分
摘要
Skype is one of the most used P2P applications on the Internet VoIP calls, instant messaging, SMS and other features are provided at a low cost to millions of users Although Skype is a closed source application, an API allows developers to build custom plugins which interact over the Skype network, taking advantage of its reliability and capability to easily bypass firewalls and NAT devices Since the protocol is completely undocumented, Skype traffic is particularly hard to analyze and to reverse engineer We propose a novel botnet model that exploits an overlay network such as Skype to build a parasitic overlay, making it extremely difficult to track the botmaster and disrupt the botnet without damaging legitimate Skype users While Skype is particularly valid for this purpose due, to its abundance of features and Its widespread installed base, our model is generically applicable to distributed applications that employ overlay networks to send direct messages between nodes (e g, peer-to-peer software with messaging capabilities) We are convinced that similar botnet models are likely to appear into the wild in the near future and that the threats they pose should not be underestimated Our contribution strives to provide the tools to correctly evaluate and understand the possible evolution and deployment of this phenomenon
更多
查看译文
关键词
overlay network,Skype network,Skype traffic,damaging legitimate Skype user,parasitic overlay,instant messaging,messaging capability,novel botnet model,NAT device,P2P application,cost-effective botnet,deep breath
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要