Tell Me You Fixed It: Evaluating Vulnerability Notifications via Quarantine Networks
Autor: | Orcun Cetin, Michel van Eeten, Carlos Gañán, Lisette Altena, Samaneh Tajalizadehkhoob |
---|---|
Rok vydání: | 2019 |
Předmět: |
Computer science
ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS Multicast DNS 020206 networking & telecommunications 02 engineering and technology Computer security computer.software_genre law.invention Empirical research Resource (project management) law Server Quarantine 0202 electrical engineering electronic engineering information engineering 020201 artificial intelligence & image processing computer Vulnerability (computing) |
Zdroj: | EuroS&P |
DOI: | 10.1109/eurosp.2019.00032 |
Popis: | Mechanisms for large-scale vulnerability notifications have been confronted with disappointing remediation rates. It has proven difficult to reach the relevant party and, once reached, to incentivize them to act. We present the first empirical study of a potentially more effective mechanism: quarantining the vulnerable resource until it is remediated. We have measured the remediation rates achieved by a medium-sized ISP for 1, 688 retail customers running open DNS resolvers or Multicast DNS services. These servers can be abused in UDP-based amplification attacks. We assess the effectiveness of quarantining by comparing remediation with two other groups: one group which was notified but not quarantined and another group where no action was taken. We find very high remediation rates for the quarantined users, 87%, even though they can self-release from the quarantine environment. Of those who received the email-only notification, 76% remediated. Surprisingly, over half of the customers who were not notified at all also remediated, though this is tied to the fact that many observations of vulnerable servers are transient. All in all, quarantining appears more effective than other notification and remediation mechanisms, but it is also clear that it can not be deployed as a general solution for Internet-wide notifications. |
Databáze: | OpenAIRE |
Externí odkaz: |