Example: dental hygienist

Understanding the Mirai Botnet - USENIX

This paper is included in the Proceedings of the 26th USENIX Security SymposiumAugust 16 18, 2017 Vancouver, BC, CanadaISB N 978 -1- 931971- 4 0 - 9 Open access to the Proceedings of the 26th USENIX Security Symposium is sponsored by USENIXU nderstanding the Mirai BotnetManos Antonakakis, Georgia Institute of Technology; Tim April, Akamai; Michael Bailey, University of Illinois, Urbana-Champaign; Matt Bernhard, University of Michigan, Ann Arbor; Elie Bursztein, Google; Jaime Cochran, Cloudflare; Zakir Durumeric and J. Alex Halderman, University of Michigan, Ann Arbor; Luca Invernizzi, Google; Michalis Kallitsis, Merit Network, Inc.; Deepak Kumar, University of Illinois, Urbana-Champaign; Chaz Lever, Georgia Institute of Technology; Zane Ma and Joshua Mason, University of Illinois, Urbana-Champaign; Damian Menscher, Google; Chad Seaman, Akamai; Nick Sullivan, Cloudflare; Kurt Thomas, Google; Yi Zhou, University of Illinois, Urbana- the Mirai Bot

3.1 Network Telescope Mirai’s indiscriminate, rapid scanning strategy lends it-self to tracking the botnet’s propagation to new hosts. We monitored all network requests to a network telescope [9] composed of 4.7 million IP address operated by Merit Network over a seven month period from July 18, 2016 to February 28, 2017.

Tags:

  Telescope

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Understanding the Mirai Botnet - USENIX

1 This paper is included in the Proceedings of the 26th USENIX Security SymposiumAugust 16 18, 2017 Vancouver, BC, CanadaISB N 978 -1- 931971- 4 0 - 9 Open access to the Proceedings of the 26th USENIX Security Symposium is sponsored by USENIXU nderstanding the Mirai BotnetManos Antonakakis, Georgia Institute of Technology; Tim April, Akamai; Michael Bailey, University of Illinois, Urbana-Champaign; Matt Bernhard, University of Michigan, Ann Arbor; Elie Bursztein, Google; Jaime Cochran, Cloudflare; Zakir Durumeric and J. Alex Halderman, University of Michigan, Ann Arbor; Luca Invernizzi, Google; Michalis Kallitsis, Merit Network, Inc.; Deepak Kumar, University of Illinois, Urbana-Champaign; Chaz Lever, Georgia Institute of Technology; Zane Ma and Joshua Mason, University of Illinois, Urbana-Champaign; Damian Menscher, Google; Chad Seaman, Akamai; Nick Sullivan, Cloudflare; Kurt Thomas, Google; Yi Zhou, University of Illinois, Urbana- the Mirai BotnetManos Antonakakis Tim April Michael Bailey Matthew Bernhard/Elie Bursztein Jaime Durumeric/J.

2 Alex Halderman/Luca Invernizzi Michalis Kallitsis Deepak Kumar Chaz Lever Zane Ma Joshua Mason Damian Menscher Chad Seaman Nick Thomas Yi Zhou Akamai Georgia Institute of Technology Google Merit Network University of Illinois Urbana-Champaign/University of MichiganAbstractThe Mirai Botnet , composed primarily of embeddedand IoT devices, took the Internet by storm in late 2016when it overwhelmed several high-profile targets withmassive distributed denial-of-service (DDoS) attacks. Inthis paper, we provide a seven-month retrospective anal-ysis of Mirai s growth to a peak of 600k infections anda history of its DDoS victims. By combining a varietyof measurement perspectives, we analyze how the bot-net emerged, what classes of devices were affected, andhow Mirai variants evolved and competed for vulnerablehosts.

3 Our measurements serve as a lens into the fragileecosystem of IoT devices. We argue that Mirai may rep-resent a sea change in the evolutionary development ofbotnets the simplicity through which devices were in-fected and its precipitous growth, demonstrate that novicemalicious techniques can compromise enough low-enddevices to threaten even some of the best-defended address this risk, we recommend technical and non-technical interventions, as well as propose future IntroductionStarting in September 2016, a spree of massive distributeddenial-of-service (DDoS) attacks temporarily crippledKrebs on Security [46], OVH [43], and Dyn [36].

4 The ini-tial attack on Krebs exceeded 600 Gbps in volume [46] among the largest on record. Remarkably, this overwhelm-ing traffic was sourced from hundreds of thousands ofsome of the Internet s least powerful hosts Internet ofThings (IoT) devices under the control of a new botnetnamed other IoT botnets such as BASHLITE [86] andCarna [38] preceded Mirai , the latter was the first toemerge as a high-profile DDoS threat. What explainsMirai s sudden rise and massive scale? A combination Denotes primary, lead, or first authorof factors efficient spreading based on Internet-widescanning, rampant use of insecure default passwords inIoT products, and the insight that keeping the Botnet sbehavior simple would allow it to infect many hetero-geneous devices all played a role.

5 Indeed, Mirai hasspawned many variants that follow the same infectionstrategy, leading to speculation that IoT botnets are thenew normal of DDoS attacks [64].In this paper, we investigate the precipitous rise of Mi-rai and the fragile IoT ecosystem it has subverted. Wepresent longitudinal measurements of the Botnet s growth,composition, evolution, and DDoS activities from Au-gust 1, 2016 to February 28, 2017. We draw from adiverse set of vantage points including network telescopeprobes, Internet-wide banner scans, IoT honeypots, C2milkers, DNS traces, and logs provided by attack vic-tims. These unique datasets enable us to conduct the firstcomprehensive analysis of Mirai and posit technical andnon-technical defenses that may stymie future track the outbreak of Mirai and find the botnetinfected nearly 65,000 IoT devices in its first 20 hoursbefore reaching a steady state population of 200,000 300,000 infections.

6 These bots fell into a narrow band ofgeographic regions and autonomous systems, with Brazil,Columbia, and Vietnam disproportionately accounting of infections. We confirm that Mirai targeted avariety of IoT and embedded devices ranging from DVRs,IP cameras, routers, and printers, but find Mirai s ultimatedevice composition was strongly influenced by the marketshares and design decisions of a handful of consumerelectronics statically analyzing over 1,000 malware samples,we document the evolution of Mirai into dozens of vari-ants propagated by multiple, competing Botnet variants attempted to improve Mirai s detectionavoidance techniques, add new IoT device targets, and in-troduce additional DNS resilience.

7 We find that Mirai har-nessed its evolving capabilities to launch over 15,000 at-tacks against not only high-profile targets ( , KrebsUSENIX Association26th USENIX Security Symposium 109308/01/2016 Mirai surfaces09/18/2016 OVH attacksbegin09/30/2016 Source code released10/21/2016 Dyn attacks10/31/2016 Liberia Lonestarattacks begin01/18/2017 Mirai author identified02/23/2017 Deutsche Telekom attacker arrested11/26/2016 Deutsche TelekomCWMP exploitSeptOctNovDecJanFeb09/21/2016 Krebs on Security peak attackFigure 1: Mirai Timeline Major attacks (red), exploits (yellow), and events (black) related to the Mirai Security, OVH, and Dyn), but also numerous gameservers, telecoms, anti-DDoS providers, and other seem-ingly unrelated sites.

8 While DDoS was Mirai s flavorof abuse, future strains of IoT malware could leverageaccess to compromised routers for ad fraud, cameras forextortion, network attached storage for bitcoin mining,or any number of applications. Mirai s reach extendedacross borders and legal jurisdictions, and it infected de-vices with little infrastructure to effectively apply securitypatches. This made defending against it a daunting , we look beyond Mirai to explore the securityposture of the IoT landscape. We find that the absence ofsecurity best practices established in response to desk-top worms and malware over the last two decades hascreated an IoT substrate ripe for exploitation.

9 However,this space also presents unique, nuanced challenges in therealm of automatic updates, end-of-life, and consumer no-tifications. Without improved defenses, IoT-based attacksare likely to remain a potent adversarial technique as bot-net variants continue to evolve and discover new nichesto infect. In light of this, Mirai seems aptly named it isJapanese for the future. 2 The Mirai BotnetMirai is a worm-like family of malware that infectedIoT devices and corralled them into a DDoS Botnet . Weprovide a brief timeline of Mirai s emergence and discussits structure and of eventsReports of Mirai appeared asearly as August 31, 2016 [89], though it was not untilmid-September, 2016 that Mirai grabbed headlines withmassive DDoS attacks targeting Krebs on Security [46]and OVH [74] (Figure 1).

10 Several additional high-profileattacks later targeted DNS provider Dyn [36] andLonestar Cell, a Liberian telecom [45]. In early 2017, theactors surrounding Mirai came to light as the Mirai authorwas identified [49]. Throughout our study, we corroborateour measurement findings with these media reports andexpand on the public information surrounding significant event in this timeline is the publicrelease of Mirai s source code on [4]. Werely on this code to develop our measurement method-ology (Section 3). Furthermore, as we detail later (Sec-tion 5), this source code release led to the proliferationof Mirai variants with competing operators.


Related search queries