BotNets Detection and Mitigation:僵尸网络的检测和缓解_第1页
BotNets Detection and Mitigation:僵尸网络的检测和缓解_第2页
BotNets Detection and Mitigation:僵尸网络的检测和缓解_第3页
BotNets Detection and Mitigation:僵尸网络的检测和缓解_第4页
BotNets Detection and Mitigation:僵尸网络的检测和缓解_第5页
已阅读5页,还剩3页未读, 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

1、.BotNets: Detection and MitigationFebruary 2003AcknowledgementsFedCIRC would like to thank the authors of the noted references for their work which was used in the preparation of this document, and the FedCIRC staff for their input and review of the document in its various iterations. FedCIRC would

2、especially like to thank Rob Thomas for his careful review and detailed comments regarding the original draft of this document.I. IntroductionThis paper discusses BotNets, which are networks of computer systems using IRC or related capabilities for communication, command, and control. The purpose of

3、 the paper is to provide background and recommendations so that network and system security administrators can recognize and defend against BotNet activity. Section 2 provides some background on IRC, and Section 3 introduces BotNets. Section 4 presents BotNet uses and Section 5 provides specific ind

4、icators of BotNet activity. Section 6 provides recommendations for mitigating the risk presented by BotNets. Sections 7 and 8 provide references and contact information, respectively.1. IRCIRC (Internet Relay Chat) is an Internet protocol 1 which allows multiple connected users to engage in a real-t

5、ime textual dialogue; the effect is that a user can monitor a "conversation" between multiple entities, and can participate in the conversation as well. IRC evolved from the BBSs (Bulletin Board Systems) prevalent prior to the explosive growth of Internet connectivity; however, where BBSs

6、required a dial-up connection and had inherent limitations in speed, functionality, and throughput, IRC only requires an Internet connection and has mitigated these limitations. Figure 1 illustrates basic IRC operation:Figure 1: Basic IRC OperationIn this simplified view, each user has connected to

7、the same IRC server; whenever any user submits a message to the server, every user sees the message. In practice, IRC servers typically provide services for multiple "channels", or discussion areas, so a user wishing to participate in a particular discussion must: (a) have an IRC client (m

8、any exist, including free), (b) know the IP address of a server hosting the desired channel, and (c) know the channel name. It is possible to password protect IRC channels (IRC passwords are called "keys") and/or the entire server, although this is rarely done for public channels and serve

9、rs; IRC operators generally control channels and servers via a command line connection not related to IRC (telnet, SSH, etc.). The default ports for the IRC service are 6665-6669/tcp, and port 6667/tcp is the most common, although this is configurable. The popularity of IRC has led to the establishm

10、ent of IRC networks 2, which are collections of connected IRC servers, providing higher capacity and redundancy (a user can connect to the desired channel on any of the network's IRC servers).A few additional background notes regarding IRC will finish setting the stage for our BotNet discussion.

11、 First, users in IRC channels are not all equal; every channel has one or more users designated as "Channel Operators". Among other powers, ChanOps (a.k.a. Ops) have the ability to arbitrarily kick users off of a channel and prevent their return. Of particular relevance to the BotNet discu

12、ssion is how ChanOp privileges are obtained, which is either (a) first come, first serve, or (b) via an Approved ChanOp (AOP) list. The AOP list is established when the channel is created and is common in the BotNet environment because (a) the BotNet creator is creating the channel, and (b) the BotN

13、et creator can leave the channel entirely without fear of losing ChanOp privileges.Second, IRC can do more than just share text messages among multiple users. Specifically:· IRC can allow file transfers between users.· IRC can allow a user on one client to exchange messages with another cl

14、ient, including command (script) execution on another client.· The above capabilities may be executed peer-to-peer or via the IRC server; the peer-to-peer communications are provided by an IRC capability called Direct Channel Connections (DCC).Third, IRC does not require a human to run the IRC

15、client. Automated programs ("bots") are widely available which connect to and monitor IRC channels. Bots were first created and used to help maintain Channel Operator status on a particular channel (they have other legitimate uses as well); the current ChanOp would establish bots with shar

16、ed ChanOp privileges on multiple client systems, thereby reducing the possibility that a channel would be orphaned and ChanOp privileges lost to another user (relevant before IRC Services with AOP lists). Bots are typically run from high-availability servers with reliable and fast Internet connectio

17、ns, and bot control is typically maintained via a shell account on the server. Bots initially allowed the human ChanOp to establish multiple bots with ChanOp privileges for a given channel, then to disconnect from the channel (possibly from the Internet); the bots would retain ChanOp status, and wou

18、ld grant that status back to the original owner when he returned (or he could connect to the bot hosts and execute commands via the bots). The introduction of IRC Services with AOP lists reduced the need for Bots to maintain ChanOp privileges, but the Bot concept and implementation remained.2. BotNe

19、tsGiven the preliminary information above, the definition of a BotNet is now obvious: a BotNet is a connected collection of IRC Bots. In this section we'll describe BotNet structure and operation, then in Section 4 we'll look at BotNet uses.The "bot" itself is actually computer cod

20、e which runs on a client system; not all bots can participate in a BotNet, but many that do are widely available. There are two main types of BotNet structures: Hub-Leaf and Channel.In a Hub-Leaf BotNet, two bots are connected by installing the bots on the target client systems, then configuring one

21、 bot as a Hub and the other as a Leaf. BotNet building continues by configuring additional Leaf bots to connect to the same Hub, resulting in a star (hub and spoke) architecture. Further, independent BotNets can be merged by joining their Hubs. Hub-Leaf BotNets do not typically use IRC for communica

22、tion, but rather communicate via bot-specific listeners on configurable ports, so each Hub-Leaf pair of ports could be unique.In a Channel BotNet (more prevalent than Hub-Leaf BotNets), bot configuration includes identifying or establishing an IRC channel (and often a password, or key) for BotNet co

23、mmunication. Each bot joins the channel, and the controller (which may or may not be a bot) issues commands by posting messages to the IRC channel, which the bots read and interpret.Installation of a bot on a client system has the same requirements as installing any application: the client system op

24、erator must intentionally perform the install, must be tricked into performing the install, or a vulnerability must be exploited to perform the install.3. BotNet UsesAs noted above, bots were originally developed to facilitate IRC channel administration and monitoring; BotNets emerged to enhance the

25、 bots' capabilities, and also to add capabilities (e.g., to establish "private" networks). As is the case with many well-intended capabilities, malicious uses were soon identified as well; two primary malicious uses of BotNets are noted below.First, BotNets enable the creation and oper

26、ation of "private" networks; traffic on these networks does not traverse the IRC server infrastructure, and so is harder to detect unless the monitor is in the path of, or part of, the private network. Such networks are widely used for file transfer and distributed file storage; of course,

27、 no controls enforce what type of files are stored or transferred, and such files may include illegal material (stolen software, illegal data, etc.). It is certainly possible to use normal IRC capabilities to exchange illegal material as well, but such activity is easier to detect.Second, BotNets ca

28、n be used to launch coordinated network attacks in the same manner as any collection of systems under single control. BotNets are most often used for Denial of Service attacks, either against Channel Operators (so that channel control may be obtained), or against distinct targets like web servers (t

29、o render them unavailable for a period of time). It is also possible to use BotNets for distributed scanning, vulnerability exploitation, distributed computation (i.e., breaking codes by brute force), email spamming/bombing, malware distribution, and any activity which can be partitioned among multi

30、ple systems.4. Recognizing BotNet ActivityThe following list presents possible indicators of BotNet activity; such indicators should not be considered absolute proof of BotNet activity, but rather should be taken in the context of the particular network, systems, and traffic involved.· Unauthor

31、ized traffic on port 6667/tcp, the default location for IRC servers. While some IRC activity may be authorized and/or non-malicious, an analysis of the servers, channels, and content involved may indicate the nature of the activity.· IRC traffic on ports other than 6667/tcp, unless specifically

32、 authorized, may indicate malicious activity.· IRC traffic which includes non-human messages. Normal IRC traffic is person-to-person and looks somewhat like human conversation; traffic which contains apparent codes, system IDs, or very structured messages may indicate bot (and BotNet) activity

33、(e.g., "(botname) System a.b.c.d online and available", or apparently random ASCII text, like "j9Gjkfr4K6dfaj").· Traffic between systems which have no legitimate reason to communicate may indicate BotNet peer-to-peer communications; high volumes of such traffic may indicate

34、 file transfers.· Floods of UDP or ICMP traffic (the most common BotNet floods) may indicate a BotNet attack in progress; when correlated with port 6665-6669/tcp traffic, BotNet activity is likely.· Attempts to compromise systems may indicate an attempt to set up a BotNet, although such ac

35、tivity has many potential uses (mostly malicious) and is worthy of investigation regardless. Such compromise activity may take the form of vulnerability probes, exploit attempts, email with executable attachments or other exploits, and downloads of executable code.· Attack traffic (which may be

36、 high volumes of legitimate-looking traffic) coming from a system is a clear indicator of a compromised system, which may or may not be BotNet-related but certainly warrants investigation.· Unexpectedly high volumes of traffic, traffic on unusual ports, and unusual system behavior should be inv

37、estigated in general; BotNets are one of many explanations for such events. 5. BotNet DefensesBotNet defenses can be grouped by phase (prevention, detection, and response) and by role (agent or target). Defenses for each of the resulting six situations (three phases and two roles for each) are prese

38、nted below:· Prevention for potential agents. Since BotNet agents are created by compromising a system, defensive recommendations mirror established recommendations for preventing system compromise. A sample of these recommendations follows:o Patch and maintain systems.o Implement and monitor p

39、erimeter defenses (including firewalls, email and attachment filtering, and browsing protection). Consider blocking ports 6665-6669/tcp in one or both directions and/or restricting source and destination IP addresses for any allowed traffic on these ports.o Enforce a safe email handling policy (bloc

40、k executable content, educate users on safe email practices).o Protect remote user systems.o Educate users regarding safe computing practices.The most common method of BotNet Agent infection is the "come and get it" method, which may use email as well as URLs transmitted via IRC, AIM, or o

41、ther messaging tools.· Prevention for potential targets. BotNets may launch any type of attack, including distributed attacks. Therefore, defensive recommendations mirror attack defense strategies in general. A sample of these recommendations follows:o Patch and maintain systems.o Implement and

42、 monitor perimeter defenses.o Establish DDoS defenses as appropriate (multiple Internet connections, IP switching ability, traffic filtering/throttling, etc.).· Detection of agent activity. The nature of BotNet agent activity is described in Section 5. Following are specific recommendations for

43、 detecting such traffic:o Monitor network traffic flows for indications of BotNet activity.o Monitor perimeter security systems for events, such as rejected connections (inbound or outbound, especially IRC), file transfers, suspect email, etc.o Monitor IDS systems for known BotNet activity (IDS sign

44、atures may detect transfers of known BotNet files and/or known BotNet communication fingerprints).o Monitor systems for behavior indicative of BotNets per the discussion in Section 5.o Monitor traffic profiles for anomalous activity; consider the occasional use of a network sniffer or similar device

45、 to build a profile of "normal" network traffic.· Detection of target activity. In addition to general attack detection techniques, BotNet attacks may be distinguished because they most often have distributed (multiple) sources; source IPs may be spoofed, but often are not. Note that

46、BotNets have been reported with as many as 25,000 agents, capable of a massive bandwidth attack from a large number of source IPs (rendering many defensive measures inadequate).· Response for agents. If BotNet agent activity is suspected, we recommend the following actions:o Consider removing t

47、he system from the network.o Consider isolating the system if a trap and trace strategy is employed; ensure that the system cannot attack other systems, but leave network connectivity intact so that the controller may be traced.o Consider a hard shutdown of the system to preserve evidence. Depending

48、 on the operational necessity of the system and the sensitivity of exposed data, this may or may not be practical. The tradeoff with leaving a system running and/or attempting to capture dynamic run-state information is that other evidence may be destroyed in the process (inadvertently or by the att

49、acker's design).o Preserve the data on the affected system and relevant system logs (Firewalls, Mail servers, IDS, DHCP server, Web proxy logs, etc.).o Report the incident to your agency CIRC and FedCIRC; report to law enforcement (or internal IG) as appropriate (most system compromises are considered violations of law).· Response for targets. If an attack from a BotNet is detected, the following actions are recommended:o The most effective BotNet attacks are resource consumption denial of service attacks. If a small set of source IPs are det

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论