首页> 外文会议>International conference on mobile, secure, and programmable networking >Enhanced Sinkhole System: Collecting System Details to Support Investigations
【24h】

Enhanced Sinkhole System: Collecting System Details to Support Investigations

机译:增强的污水池系统:收集系统详细信息以支持调查

获取原文

摘要

Adversaries use increasingly complex and sophisticated tactics, techniques and procedures to compromise single computer systems and complete IT environments. Most of the standard detection and prevention systems are not able to provide a decent level of protection against sophisticated attacks, because adversaries are able to bypass various detection approaches. Therefore, additional solutions are needed to improve the prevention and detection of complex attacks. DNS sinkholing is one approach that can be used to redirect known malicious connections to dedicated sinkhole systems. The objective of these sinkhole systems is to interrupt the communication of the malware and to gather details about it. Due to the fact that current sinkhole systems focus on the collection of network related information, the gathered details cannot be used to support investigations in a comprehensive way and to improve detection and prevention capabilities. In this paper, we propose a new approach for an enhanced sinkhole system that is able collect detailed information about potentially infected systems and the corresponding malware that is executed. This system is able to gather details, such as open network connections, running processes and process memory, to provide relevant information about the malware behavior and the used methods. The approach makes use of built-in remote management capabilities and standard commands as well as functions of the operating system to gather the details. This also ensures that the footprint of the collection approach is small and therefore also difficult to recognize by a malware. For the evaluation of the proposed approach, we executed real-world malware and collected details from the infected system with a prototypically implemented enhanced sinkhole system. The gathered information shows that these details can be used to support investigations and to improve security solutions.
机译:攻击者使用越来越复杂和复杂的策略,技术和程序来破坏单个计算机系统和完整的IT环境。大多数标准检测和防御系统都无法提供针对复杂攻击的适当防护,因为攻击者可以绕过各种检测方法。因此,需要其他解决方案来改进对复杂攻击的预防和检测。 DNS沉陷是一种可用于将已知恶意连接重定向到专用沉陷系统的方法。这些漏洞系统的目的是中断恶意软件的通信并收集有关它的详细信息。由于当前的污水坑系统侧重于收集与网络相关的信息,因此,所收集的详细信息无法用于全面支持调查并提高检测和预防能力。在本文中,我们提出了一种用于增强型污水坑系统的新方法,该方法能够收集有关潜在感染的系统和所执行的相应恶意软件的详细信息。该系统能够收集详细信息,例如开放的网络连接,运行的进程和进程内存,以提供有关恶意软件行为和使用的方法的相关信息。该方法利用内置的远程管理功能和标准命令以及操作系统功能来收集详细信息。这也确保了收集方法的占用空间很小,因此也很难被恶意软件识别。为了评估提议的方法,我们执行了现实世界中的恶意软件,并使用原型实现的增强型污水池系统从受感染的系统中收集了详细信息。收集的信息表明,这些详细信息可用于支持调查和改进安全解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号