-
CSE543 - Introduction to Computer and Network Security Page
CSE543 Computer and Network Security Module: Internet Malware
Professor Trent Jaeger Fall 2010
1
CSE543 Computer and Network Security Module: Internet Malware - - PowerPoint PPT Presentation
CSE543 - Introduction to Computer and Network Security Page
1
CMPSC443 - Introduction to Computer and Network Security Page
2
CMPSC443 - Introduction to Computer and Network Security Page
3
CMPSC443 - Introduction to Computer and Network Security Page
500,000,000 1,000,000,000 1,500,000,000 2,000,000,000 2,500,000,000 3,000,000,000 3,500,000,000 4,000,000,000 4,500,000,000 5,000,000,000
4
CMPSC443 - Introduction to Computer and Network Security Page
5
CMPSC443 - Introduction to Computer and Network Security Page
dormant 28-31st)
6
CMPSC443 - Introduction to Computer and Network Security Page
7
CMPSC443 - Introduction to Computer and Network Security Page
8
500,000,000 1,000,000,000 1,500,000,000 2,000,000,000 2,500,000,000 3,000,000,000 3,500,000,000 4,000,000,000 4,500,000,000 5,000,000,000CMPSC443 - Introduction to Computer and Network Security Page
Shield
Network Traffic
9
CMPSC443 - Introduction to Computer and Network Security Page
10
CMPSC443 - Introduction to Computer and Network Security Page
11
CMPSC443 - Introduction to Computer and Network Security Page
12
CMPSC443 - Introduction to Computer and Network Security Page
addresses (e.g., 192.168.27.254)
Host Host Host Host Host Host Host Host Host
adversary Broadcast victim
13
CMPSC443 - Introduction to Computer and Network Security Page
14
CMPSC443 - Introduction to Computer and Network Security Page
15
CMPSC443 - Introduction to Computer and Network Security Page
16
CMPSC443 - Introduction to Computer and Network Security Page
17
CMPSC443 - Introduction to Computer and Network Security Page
18
CMPSC443 - Introduction to Computer and Network Security Page
19
CMPSC443 - Introduction to Computer and Network Security Page
20
CMPSC443 - Introduction to Computer and Network Security Page
21
CMPSC443 - Introduction to Computer and Network Security Page
22
CMPSC443 - Introduction to Computer and Network Security Page
23
CMPSC443 - Introduction to Computer and Network Security Page
24
CMPSC443 - Introduction to Computer and Network Security Page
25
CMPSC443 - Introduction to Computer and Network Security Page
R1 R2 R3
26
CMPSC443 - Introduction to Computer and Network Security Page
27
CMPSC443 - Introduction to Computer and Network Security Page
28
CSE543 - Introduction to Computer and Network Security Page
29
CSE543 - Introduction to Computer and Network Security Page
30
CSE543 - Introduction to Computer and Network Security Page
31
– 100-20,000 bots/net
spread around the world
– Different geographic concentrations
Activities we have seen Stealing CD Keys: ying!ying@ying.2.tha.yang PRIVMSG #atta :BGR|0981901486 $getcdkeys BGR|0981901486!nmavmkmyam@212.91.170.57 PRIVMSG #atta :Microsoft Windows Product ID CD Key: (55274-648-5295662-23992). BGR|0981901486!nmavmkmyam@212.91.170.57 PRIVMSG #atta :[CDKEYS]: Search completed. Reading a user's clipboard: B][!Guardian@globalop.xxx.xxx PRIVMSG ##chem## :~getclip Ch3m|784318!~zbhibvn@xxx-7CCCB7AA.click-network.com PRIVMSG ##chem## :- [Clipboard Data]- Ch3m|784318!~zbhibvn@xxx-7CCCB7AA.click-network.com PRIVMSG ##chem## :If You think the refs screwed the seahawks over put your name down!!! DDoS someone: devil!evil@admin.of.hell.network.us PRIVMSG #t3rr0r0Fc1a :!pflood 82.147.217.39 443 1500 s7n|2K503827!s7s@221.216.120.120 PRIVMSG #t3rr0r0Fc1a :\002Packets\002 \002D\002one \002;\002>\n s7n|2K503827!s7s@221.216.120.120 PRIVMSG #t3rr0r0Fc1a flooding....\n Set up a web-server (presumably for phishing): [DeXTeR]!alexo@l85-130-136-193.broadband.actcom.net.il PRIVMSG [Del]29466 :.http 7564 c:\\ [Del]38628!zaazbob@born113.athome233.wau.nl PRIVMSG _[DeXTeR] :[HTTPD]: Server listening on IP: 10.0.2.100:7564, Directory: c:\\.
piracy mining attacks hosting
CSE543 - Introduction to Computer and Network Security Page
32
CSE543 - Introduction to Computer and Network Security Page
“A botnet is comparable to compulsory military service for windows boxes”
33
IRC Server Bots (Zombies)
Find and infect more machines!
CSE543 - Introduction to Computer and Network Security Page
34
Bots usually require some form of authentication from their botmaster
CSE543 - Introduction to Computer and Network Security Page
35
CSE543 - Introduction to Computer and Network Security Page
36
Server Server Server Server Server
CSE543 - Introduction to Computer and Network Security Page
37
#HINDI-FILMZ :#1 294x [698M] [Movie] Dil Bechara Pyar Ka Mara DvD-RiP [ Full / AVI / 2001 ] #HINDI-FILMZ :#2 126x [141K] [English Subtitles] Dil Bechara Pyar Ka Mara #HINDI-FILMZ :** 2 packs ** 3 of 3 slots open, Record: 45.3KB/s #HINDI-FILMZ :** Bandwidth Usage ** Current: 0.0KB/s, Record: 304.5KB/s #HINDI-FILMZ :** To request a file type: /"/msg [HF]-[Street-Hunk]-30 xdcc send #x/" ** #HINDI-FILMZ :** -= #Hindi-Filmz=- ** #HINDI-FILMZ :** I M 100% Desi !! ** #HINDI-FILMZ :Total Offered: 698.5 MB Total Transferred: 206.57 GB #HINDI-FILMZ :#1 294x [698M] [Movie] Dil Bechara Pyar Ka Mara DvD-RiP [ Full / AVI / 2001 ] #HINDI-FILMZ :#2 126x [141K] [English Subtitles] Dil Bechara Pyar Ka Mara #HINDI-FILMZ :** 2 packs ** 3 of 3 slots open, Record: 45.3KB/s #HINDI-FILMZ :** Bandwidth Usage ** Current: 0.0KB/s, Record: 304.5KB/s #HINDI-FILMZ :** To request a file type: /"/msg [HF]-[Street-Hunk]-30 xdcc send #x/" ** #HINDI-FILMZ :** -= #Hindi-Filmz=- ** #HINDI-FILMZ :** I M 100% Desi !! ** #HINDI-FILMZ :Total Offered: 698.5 MB Total Transferred: 206.57 GB
That’s a lot of movies served! ( ~ 300)
CSE543 - Introduction to Computer and Network Security Page 38
CSE543 - Introduction to Computer and Network Security Page 39
CSE543 - Introduction to Computer and Network Security Page 40
CSE543 - Introduction to Computer and Network Security Page
41
CSE543 - Introduction to Computer and Network Security Page
42
#queries by host #queries for host
CSE543 - Introduction to Computer and Network Security Page
43
CSE543 - Introduction to Computer and Network Security Page
44
CSE543 - Introduction to Computer and Network Security Page
45
CSE543 - Introduction to Computer and Network Security Page
46
CSE543 - Introduction to Computer and Network Security Page
47
CSE543 - Introduction to Computer and Network Security Page
48
CSE543 - Introduction to Computer and Network Security Page 49
CSE543 - Introduction to Computer and Network Security Page 50
Temporary migration
between bot channels)
period
Cloning
CSE543 - Introduction to Computer and Network Security Page
51