A Practical Approach for Taking Down Avalanche Botnets Under Real-World Constraints
Victor Le Pochat, Tim Van hamme, Sourena Maroofi, Tom van Goethem, Davy Preuveneers, Andrzej Duda, Wouter Joosen, Maciej Korczynski
摘要
In 2016, law enforcement dismantled the infrastructure of the Avalanche bulletproof hosting service, the largest takedown of a cybercrime operation so far. The malware families supported by Avalanche use Domain Generation Algorithms (DGAs) to generate random domain names for controlling their botnets. The takedown proactively targets these presumably malicious domains; however, as coincidental collisions with legitimate domains are possible, investigators must first classify domains to prevent undesirable harm to website owners and botnet victims. The constraints of this real-world takedown (proactive decisions without access to malware activity, no bulk patterns and no active connections) mean that approaches from the state of the art cannot be applied. The problem of classifying thousands of registered DGA domain names therefore required an extensive, painstaking manual effort by law enforcement investigators. To significantly reduce this effort without compromising correctness, we develop a model that automates the classification. Through a synergetic approach, we achieve an accuracy of 97.6% with ground truth from the 2017 and 2018 Avalanche takedowns; for the 2019 takedown, this translates into a reduction of 76.9% in manual investigation effort. Furthermore, we interpret the model to provide investigators with insights into how benign and malicious domains differ in behavior, which features and data sources are most important, and how the model can be applied according to the practical requirements of a real-world takedown.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Practical Attacks Against DNS Reputation SystemsTillson Galloway, Kleanthis Karakolios, Zane Ma, Roberto Perdisci 等S&P 2024 · 被引用 13 次
- C3PO: Large-Scale Study Of Covert Monitoring of C&C Servers via Over-Permissioned Protocol InfiltrationJonathan Fuller, Ranjita Pai Kasturi, Amit Kumar Sikder, Haichuan Xu 等CCS 2021 · 被引用 6 次
- Exposing the Roots of DNS Abuse: A Data-Driven Analysis of Key Factors Behind Phishing Domain RegistrationsYevheniya Nosyk, Maciej Korczynski, Carlos Gañán, Sourena Maroofi 等CCS 2025 · 被引用 1 次
- From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPRChaoyi Lu, Baojun Liu, Yiming Zhang, Zhou Li 等NDSS 2021
它引用的顶会 Paper11
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- A Comprehensive Measurement Study of Domain Generating MalwareDaniel Plohmann, Khaled Yakdan, Michael Klatt, Johannes Bader 等USENIX Security 2016 · 被引用 252 次
- FANCI : Feature-based Automated NXDomain Classification and IntelligenceSamuel Schüppen, Dominik Teubert, Patrick Herrmann, Ulrike MeyerUSENIX Security 2018 · 被引用 164 次
- PREDATOR: Proactive Recognition and Elimination of Domain Abuse at Time-Of-RegistrationShuang Hao, Alex Kantchelian, Brad Miller, Vern Paxson 等CCS 2016 · 被引用 133 次
相关 Paper
- Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downsEihal Alowaisheq, Peng Wang, Sumayah A. Alrwais, Xiaojing Liao 等NDSS 2019 · 被引用 48 次
- Platforms in Everything: Analyzing Ground-Truth Data on the Anatomy and Economics of Bullet-Proof HostingArman Noroozian, Jan Koenders, Eelco van Veldhuizen, Carlos Hernandez Gañán 等USENIX Security 2019 · 被引用 40 次
- Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire ServicesAnh V. Vu, Ben Collier, Daniel R. Thomas, John Kristoff 等USENIX Security 2025
- Under the Shadow of Sunshine: Understanding and Detecting Bulletproof Hosting on Legitimate Service Provider NetworksSumayah A. Alrwais, Xiaojing Liao, Xianghang Mi, Peng Wang 等S&P 2017 · 被引用 51 次
- MANTIS: Detection of Zero-Day Malicious Domains Leveraging Low Reputed Hosting InfrastructureFatih Deniz, Mohamed Nabeel, Ting Yu, Issa KhalilS&P 2025
