서브메뉴
검색
Names to Conjure With: Measuring and Combating Online Adversaries by Examining Their Use of Naming Systems- [electronic resource]
Names to Conjure With: Measuring and Combating Online Adversaries by Examining Their Use of Naming Systems- [electronic resource]
상세정보
- 자료유형
- 학위논문파일 국외
- 최종처리일시
- 20240214100120
- ISBN
- 9798379760281
- DDC
- 004
- 저자명
- Randall, Audrey.
- 서명/저자
- Names to Conjure With: Measuring and Combating Online Adversaries by Examining Their Use of Naming Systems - [electronic resource]
- 발행사항
- [S.l.]: : University of California, San Diego., 2023
- 발행사항
- Ann Arbor : : ProQuest Dissertations & Theses,, 2023
- 형태사항
- 1 online resource(178 p.)
- 주기사항
- Source: Dissertations Abstracts International, Volume: 85-01, Section: A.
- 주기사항
- Advisor: Schulman, Aaron;Voelker, Geoffrey M.;Savage, Stefan.
- 학위논문주기
- Thesis (Ph.D.)--University of California, San Diego, 2023.
- 사용제한주기
- This item must not be sold to any third party vendors.
- 초록/해제
- 요약Defenders combat online adversaries by understanding their behavior, the resources they depend on, and their strategies and tactics. However, measuring adversarial activity directly is often challenging, because adversaries take steps to obfuscate their behavior and evade detection by defenders. To overcome this challenge, defenders may leverage the knowledge that adversaries rely on licit, external resources, whose business models do not require secrecy. These resources may therefore leak valuable information, including the prevalence of threats, the relative effectiveness of competing adversaries, the strategies adversaries use, or the resources and infrastructure they rely upon. Such information can help defenders prioritize threats and decide which components of an ecosystem to target for interventions. This dissertation presents a new framework for designing measurement techniques and interventions for online adversaries: I leverage the information leaked by naming systems. I show that because naming systems are both lists of an adversary's resources and critical resources themselves, observing them enables defenders to measure adversaries' prevalence, compare their harmfulness, analyze their infrastructure, and more, thus improving interventions by identifying the most effective resources to target and prioritizing the most dangerous threats.I present four studies that each leverage some aspect of a naming system to measure an adversary's behavior and inform defenses against it. First, I measure the prevalence of overt stalkerware in the wild, by using privacy-preserving DNS cache snooping on four public DNS resolvers. Second, I determine the location in the network of DNS redirection attacks, by exploiting the format of certain special DNS responses. Third, I investigate the abuse of blockchain-based naming systems (BNSes) by malware operators, and design interventions leveraging BNS components to disrupt malware campaigns. Finally, I measure an emerging web privacy threat, UID smuggling, by participating in the naming system built by trackers to link user identifiers with behavioral data. In each case, I measure or design defenses against an adversary that would be difficult to study without examining the information leaked by a naming system.
- 일반주제명
- Computer science.
- 일반주제명
- Information science.
- 키워드
- Naming systems
- 키워드
- DNS redirection
- 기타저자
- University of California, San Diego Computer Science and Engineering
- 기본자료저록
- Dissertations Abstracts International. 85-01A.
- 기본자료저록
- Dissertation Abstract International
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008240612s2023 us |||||||||||||||c||eng d■001000016931800
■00520240214100120
■006m o d
■007cr#unu||||||||
■020 ▼a9798379760281
■035 ▼a(MiAaPQ)AAI30423814
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a004
■1001 ▼aRandall, Audrey.
■24510▼aNames to Conjure With: Measuring and Combating Online Adversaries by Examining Their Use of Naming Systems▼h[electronic resource]
■260 ▼a[S.l.]:▼bUniversity of California, San Diego. ▼c2023
■260 1▼aAnn Arbor :▼bProQuest Dissertations & Theses, ▼c2023
■300 ▼a1 online resource(178 p.)
■500 ▼aSource: Dissertations Abstracts International, Volume: 85-01, Section: A.
■500 ▼aAdvisor: Schulman, Aaron;Voelker, Geoffrey M.;Savage, Stefan.
■5021 ▼aThesis (Ph.D.)--University of California, San Diego, 2023.
■506 ▼aThis item must not be sold to any third party vendors.
■520 ▼aDefenders combat online adversaries by understanding their behavior, the resources they depend on, and their strategies and tactics. However, measuring adversarial activity directly is often challenging, because adversaries take steps to obfuscate their behavior and evade detection by defenders. To overcome this challenge, defenders may leverage the knowledge that adversaries rely on licit, external resources, whose business models do not require secrecy. These resources may therefore leak valuable information, including the prevalence of threats, the relative effectiveness of competing adversaries, the strategies adversaries use, or the resources and infrastructure they rely upon. Such information can help defenders prioritize threats and decide which components of an ecosystem to target for interventions. This dissertation presents a new framework for designing measurement techniques and interventions for online adversaries: I leverage the information leaked by naming systems. I show that because naming systems are both lists of an adversary's resources and critical resources themselves, observing them enables defenders to measure adversaries' prevalence, compare their harmfulness, analyze their infrastructure, and more, thus improving interventions by identifying the most effective resources to target and prioritizing the most dangerous threats.I present four studies that each leverage some aspect of a naming system to measure an adversary's behavior and inform defenses against it. First, I measure the prevalence of overt stalkerware in the wild, by using privacy-preserving DNS cache snooping on four public DNS resolvers. Second, I determine the location in the network of DNS redirection attacks, by exploiting the format of certain special DNS responses. Third, I investigate the abuse of blockchain-based naming systems (BNSes) by malware operators, and design interventions leveraging BNS components to disrupt malware campaigns. Finally, I measure an emerging web privacy threat, UID smuggling, by participating in the naming system built by trackers to link user identifiers with behavioral data. In each case, I measure or design defenses against an adversary that would be difficult to study without examining the information leaked by a naming system.
■590 ▼aSchool code: 0033.
■650 4▼aComputer science.
■650 4▼aInformation science.
■653 ▼aOnline adversaries
■653 ▼aNaming systems
■653 ▼aDNS redirection
■653 ▼aBlockchain-based naming systems
■690 ▼a0984
■690 ▼a0723
■71020▼aUniversity of California, San Diego▼bComputer Science and Engineering.
■7730 ▼tDissertations Abstracts International▼g85-01A.
■773 ▼tDissertation Abstract International
■790 ▼a0033
■791 ▼aPh.D.
■792 ▼a2023
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T16931800▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.
■980 ▼a202402▼f2024


