Intervening in the market for DoS-for-hire services
Ben Collier Co-authors: Daniel Thomas, Richard Clayton, Alice Hutchings, Ildiko Pete Cambridge Cybercrime Centre
Intervening in the market for DoS-for-hire services Ben Collier - - PowerPoint PPT Presentation
Intervening in the market for DoS-for-hire services Ben Collier Co-authors: Daniel Thomas, Richard Clayton, Alice Hutchings, Ildiko Pete Cambridge Cybercrime Centre Contents Cybercrime and communities Booter services Law enforcement
Ben Collier Co-authors: Daniel Thomas, Richard Clayton, Alice Hutchings, Ildiko Pete Cambridge Cybercrime Centre
are different kinds of disruption?
effective?
networks are important
factors
cryptomarkets, IRC networks, chat channels and hacker forums
form
users, schools, businesses, infrastructure
traffic
unskilled users
capacity to users
Discord channels and Google
thrown off
the top ten
challenging
cryptomarkets)
and is limited in effect
quantitative approaches
sourcing attack power – botnets and reflectors
booters try to use us for attacks) and observe attacks in real time as they occur
(includes botnet attacks)
modelling to estimate effect sizes
Our secret honeypot Attack server
smallish 2 week dips, localized
deep cut to the market, growth suppressed for around 10 weeks
Daily attacks
10000 20000 30000 40000 50000 60000 70000 80000 90000 100000 10/9/17 11/9/17 12/9/17 1/9/18 2/9/18 3/9/18 4/9/18 5/9/18 6/9/18 7/9/18 8/9/18 9/9/18 10/9/18 11/9/18 12/9/18 1/9/19 2/9/19 3/9/19 4/9/19 5/9/19 6/9/19
attack time series (accounting for trend and seasonality)
intervention
doesn’t stimulate the market in the way it does for
weeks where they do occur
market (Hackforums and FBI Christmas Operation)
channels
community
server providers – the people who run the infrastructure
which had a huge impact on many booters
the game” set their booters back up for a fortnight immediately after the raid
relatively low-paid – effectively a low- level admin job
source methods from Pastebin, or buy from private sellers
“Its so unpredictable. I expect the community surrounding it to die. There will always be a demand for ddos. Lots of factors. Lots of people are starting to see what I and lots of others see. A place where you learn nothing new and do not go much of
[rather than move onto other types of crime] That’s what I pretty much did” Booter provider “And after doing for almost a year, I lost all motivation, and really didn’t care anymore. So I just left and went on with life. It wasn’t challenging enough at all. Creating a stresser is easy. Providing the power to run it is the tricky part. And when you have to put all your effort, all your attention. When you have to sit infront of a computer screen and scan, filter, then filter again over 30 amps per 4 hours it gets annoying” Booter provider
neutralisations
them, users believe (correctly) that providers are taking the bigger risk
plans etc. are risky purchase as most fold after a few weeks
with growing too fast
inaccessible
interventions
takedowns appear to suppress the market
sentencing
broader market
involved than to dissuade existing users – but high turnover so may be a long-term strategy – normative rather than deterrent