Benvinguts al Repositori Digital de la UPF

Leveraging bitcoin testnet for bidirectional botnet command and control systems

Mostra el registre parcial de l'element

dc.contributor.author Franzoni, Francesco
dc.contributor.author Abellán Álvarez, Iván
dc.contributor.author Daza, Vanesa
dc.date.accessioned 2020-10-09T10:26:05Z
dc.date.available 2020-10-09T10:26:05Z
dc.date.issued 2020
dc.identifier.citation Franzoni F, Daza V, Abellán I. Leveraging bitcoin testnet for bidirectional botnet command and control systems. Paper presented at: Financial Cryptography and Data Security 2020; 2020 Feb 10-14; Kota Kinabalu, Sabah, Malaysia.
dc.identifier.uri http://hdl.handle.net/10230/45458
dc.description Comunicació presentada a: Financial Cryptography and Data Security 2020; celebrat del 10 al 14 de febrer de 2020 a Kota Kinabalu, Sabah, Malaysia.
dc.description.abstract Over the past twenty years, the number of devices connected to the Internet grew exponentially. Botnets bene ted from this rise to increase their size and the magnitude of their attacks. However, they still have a weak point in their Command & Control (C&C) system, which is often based on centralized services or require a complex infrastructure to keep operating without being taken down by authorities. The recent spread of blockchain technologies may give botnets a powerful tool to make them very hard to disrupt. Recent research showed how it is possi- ble to embed C&C messages in Bitcoin transactions, making them nearly impossible to block. Nevertheless, transactions have a cost and allow very limited amounts of data to be transmitted. Because of that, only mes- sages from the botmaster to the bots are sent via Bitcoin, while bots are assumed to communicate through external channels. Furthermore, for the same reason, Bitcoin-based messages are sent in clear. In this pa- per we show how, using Bitcoin Testnet, it is possible to overcome these limitations and implement a cost-free, bidirectional, and encrypted C&C channel between the botmaster and the bots. We propose a communica- tion protocol and analyze its viability in real life. Our results show that this approach would enable a botmaster to build a robust and hard-to- disrupt C&C system at virtually no cost, thus representing a realistic threat for which countermeasures should be devised.
dc.description.sponsorship The work of Federico Franzoni is partly supported by the Spanish Ministry of Economy and Competitiveness under the Maria de Maeztu Units of Excellence Programme (MDM-2015-0502). Vanesa Daza was supported by Project RTI2018-102112-B-I00 (AEI/FEDER,UE).
dc.format.mimetype application/pdf
dc.language.iso eng
dc.rights © IFCA https://fc20.ifca.ai/preproceedings/71.pdf
dc.title Leveraging bitcoin testnet for bidirectional botnet command and control systems
dc.type info:eu-repo/semantics/conferenceObject
dc.subject.keyword Blockchain
dc.subject.keyword Bitcoin
dc.subject.keyword Security
dc.subject.keyword Botnets
dc.subject.keyword C&C
dc.rights.accessRights info:eu-repo/semantics/openAccess
dc.type.version info:eu-repo/semantics/acceptedVersion

Thumbnail

Aquest element apareix en la col·lecció o col·leccions següent(s)

Mostra el registre parcial de l'element

Cerca


Cerca avançada

Visualitza

El meu compte

Estadístiques

Amb col·laboració de Complim Participem