Cleaning Up the Internet of Evil Things: Real-World Evidence on ISP and Consumer Efforts to Remove Mirai
Orçun Çetin, Carlos Gañán, Lisette Altena, Takahiro Kasama, Daisuke Inoue, Kazuki Tamiya, Ying Tie, Katsunari Yoshioka, Michel van Eeten
摘要
With the rise of IoT botnets, the remediation of infected devices has become a critical task. As over 87% of these devices reside in broadband networks, this task will fall primarily to consumers and the Internet Service Providers. We present the first empirical study of IoT malware cleanup in the wild -- more specifically, of removing Mirai infections in the network of a medium-sized ISP. To measure remediation rates, we combine data from an observational study and a randomized controlled trial involving 220 consumers who suffered a Mirai infection together with data from honeypots and darknets. We find that quarantining and notifying infected customers via a walled garden, a best practice from ISP botnet mitigation for conventional malware, remediates 92% of the infections within 14 days. Email-only notifications have no observable impact compared to a control group where no notifications were sent. We also measure surprisingly high natural remediation rates of 58-74% for this control group and for two reference networks where users were also not notified. Even more surprising, reinfection rates are low. Only 5% of the customers who remediated suffered another infection in the five months after our first study. This stands in contrast to our lab tests, which observed reinfection of real IoT devices within minutes -- a discrepancy for which we explore various different possible explanations, but find no satisfactory answer. We gather data on customer experiences and actions via 76 phone interviews and the communications logs of the ISP. Remediation succeeds even though many users are operating from the wrong mental model -- e.g., they run anti-virus software on their PC to solve the infection of an IoT device. While quarantining infected devices is clearly highly effective, future work will have to resolve several remaining mysteries. Furthermore, it will be hard to scale up the walled garden solution because of the weak incentives of the ISPs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court 等USENIX Security 2021 · 被引用 109 次
- Examining Mirai's Battle over the Internet of ThingsHarm Griffioen, Christian DoerrCCS 2020 · 被引用 81 次
- Dominance as a New Trusted Computing Primitive for the Internet of ThingsMeng Xu, Manuel Huber, Zhichuang Sun, Paul England 等S&P 2019 · 被引用 61 次
- United We Stand: Collaborative Detection and Mitigation of Amplification DDoS Attacks at ScaleDaniel Wagner, Daniel Kopp, Matthias Wichtlhuber, Christoph Dietzel 等CCS 2021 · 被引用 50 次
- IXP scrubber: learning from blackholing traffic for ML-driven DDoS detection at scaleMatthias Wichtlhuber, Eric Strehle, Daniel Kopp, Lars Prepens 等SIGCOMM 2022 · 被引用 35 次
它引用的顶会 Paper4
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami 等USENIX Security 2016 · 被引用 149 次
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns 等USENIX Security 2016 · 被引用 130 次
- Didn't You Hear Me? - Towards More Successful Web Vulnerability NotificationsBen Stock, Giancarlo Pellegrino, Frank Li, Michael Backes 等NDSS 2018 · 被引用 86 次
相关 Paper
- Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic ServiceTakayuki Sasaki, Tomoya Inazawa, Youhei Yamaguchi, Simon Parkin 等USENIX Security 2025
- Examining Consumer Reviews to Understand Security and Privacy Issues in the Market of Smart Home DevicesSwaathi Vetrivel, Veerle van Harten, Carlos Hernandez Gañán, Michel van Eeten 等USENIX Security 2023
- Could you clean up the Internet with a Pit of Tar? Investigating tarpit feasibility on Internet wormsHarm Griffioen, Christian DoerrS&P 2023
- Understanding Linux MalwareEmanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide BalzarottiS&P 2018 · 被引用 203 次
- How to Count Bots in Longitudinal Datasets of IP AddressesLeon Böck, Dave Levin, Ramakrishna Padmanabhan, Christian Doerr 等NDSS 2023
