An Empirical Study of HTTP-based Financial Botnets
Autor: | Richard Enbody, Sherali Zeadally, Aditya K Sood |
---|---|
Rok vydání: | 2016 |
Předmět: |
Finance
business.industry Computer science Internet privacy Botnet 020206 networking & telecommunications 02 engineering and technology Mariposa botnet Computer security computer.software_genre Empirical research Srizbi botnet 020204 information systems 0202 electrical engineering electronic engineering information engineering Command and control Malware The Internet Electrical and Electronic Engineering business computer Asprox botnet |
Zdroj: | IEEE Transactions on Dependable and Secure Computing. 13:236-251 |
ISSN: | 1545-5971 |
DOI: | 10.1109/tdsc.2014.2382590 |
Popis: | Cyber criminals are covertly attacking critical infrastructures, and botnets are a common component of those attacks. In recent years, botnets have been shifting their focus from broad-based attacks to more targeted ones such as attacking financial institutions, especially banks. The primary reason for this shift towards financial institutions is that, where the money is. We present an empirical study of the components, features and operations of some of the most widely deployed HTTP-based financial botnets (such as Zeus, SpyEye, ICE 1X, Citadel, Carberp, Tinba, Bugat and Shylock). Our study provides critical insights into the design of these botnets and should help the security community to generate intelligence and develop more robust security solutions to defend against cyber attacks by these botnets. In addition, our comparative analysis of insidious techniques pertaining to Command and Control (C&C) communication, system exploitation and data exfiltration also provides an effective and a holistic view of the capabilities of HTTP-based financial botnets. This study also highlights the evolution of various HTTP-based financial botnets over a period of time. Finally, we discuss security solutions that can help mitigate some of the techniques used by HTTP-based financial botnets. |
Databáze: | OpenAIRE |
Externí odkaz: |