본문

서브메뉴

Towards Understanding the Lifecycle of Malicious Network Infrastructure
Towards Understanding the Lifecycle of Malicious Network Infrastructure
Towards Understanding the Lifecycle of Malicious Network Infrastructure

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20260202105331
ISBN  
9798263324865
DDC  
005.8
저자명  
Avgetidis, Athanasios.
서명/저자  
Towards Understanding the Lifecycle of Malicious Network Infrastructure
발행사항  
[Sl] : Georgia Institute of Technology, 2025
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2025
형태사항  
152 p
주기사항  
Source: Dissertations Abstracts International, Volume: 87-05, Section: A.
주기사항  
Advisor: Antonakakis, Manos;Keromytis, Angelos.
학위논문주기  
Thesis (Ph.D.)--Georgia Institute of Technology, 2025.
초록/해제  
요약Network infrastructure is an important component of malicious cyber operations. From novice attacks conducted by script kiddies to highly sophisticated threats backed by nationstates, network infrastructure is being utilized for command and control, data exfiltration, malware hosting, and social engineering, among others. Over the years, while there have been several studies that have focused on detecting, blocking, and characterizing malicious infrastructure, the temporal dynamics of how this infrastructure changes over time and the characteristics of the stakeholders interacting with it have often been overlooked. This thesis shows that the temporal analysis of malicious infrastructure reveals network attributes that can characterize the stakeholders that interact with it. The systematic analysis of such network attributes can aid the accurate discovery of previously unreported malicious infrastructure and increase our awareness of the behaviors of the stakeholders that interact with it.Through longitudinal empirical studies and novel methodologies, this thesis demonstrates the importance of accounting for the temporal dynamics of malicious network infrastructure. Specifically, it introduces a novel methodology that accurately identifies historically utilized IP infrastructure from domain names of sophisticated threats, which expands the publicly reported IP knowledge by 3.06 times. It also showcases how the temporal analysis of malicious network infrastructure can help threat analysts and security practitioners better understand the quantitative distributions of the network interactions of the stakeholders (i.e., scanners, security vendors, victims, and threat actors). More precisely, this thesis pinpoints the minimum network log retention window for uncovering at least 90% of the infrastructure of sophisticated attacks down to 25 months and characterizes for the first time the lifecycle of network requests into malware-related domain names from the upper DNS hierarchy. These insights have applicable takeaways for log retention policies for network data and victim and infrastructure analysis studies using DNS datasets.
일반주제명  
Malware
일반주제명  
Threats
일반주제명  
Scanners
일반주제명  
Cybercrime
일반주제명  
URLs
일반주제명  
Criminology
기타저자  
Georgia Institute of Technology.
기본자료저록  
Dissertations Abstracts International. 87-05A.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008260126s2025        us                              c    eng  d
■001000017360267
■00520260202105331
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798263324865
■035    ▼a(MiAaPQ)AAI32307950
■035    ▼a(MiAaPQ)GeorgiaTech78717
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a005.8
■1001  ▼aAvgetidis,  Athanasios.
■24510▼aTowards  Understanding  the  Lifecycle  of  Malicious  Network  Infrastructure
■260    ▼a[Sl]▼bGeorgia  Institute  of  Technology▼c2025
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2025
■300    ▼a152  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  87-05,  Section:  A.
■500    ▼aAdvisor:  Antonakakis,  Manos;Keromytis,  Angelos.
■5021  ▼aThesis  (Ph.D.)--Georgia  Institute  of  Technology,  2025.
■520    ▼aNetwork  infrastructure  is  an  important  component  of  malicious  cyber  operations.  From  novice  attacks  conducted  by  script  kiddies  to  highly  sophisticated  threats  backed  by  nationstates,  network  infrastructure  is  being  utilized  for  command  and  control,  data  exfiltration,  malware  hosting,  and  social  engineering,  among  others.  Over  the  years,  while  there  have  been  several  studies  that  have  focused  on  detecting,  blocking,  and  characterizing  malicious  infrastructure,  the  temporal  dynamics  of  how  this  infrastructure  changes  over  time  and  the  characteristics  of  the  stakeholders  interacting  with  it  have  often  been  overlooked.  This  thesis  shows  that  the  temporal  analysis  of  malicious  infrastructure  reveals  network  attributes  that  can  characterize  the  stakeholders  that  interact  with  it.  The  systematic  analysis  of  such  network  attributes  can  aid  the  accurate  discovery  of  previously  unreported  malicious  infrastructure  and  increase  our  awareness  of  the  behaviors  of  the  stakeholders  that  interact  with  it.Through  longitudinal  empirical  studies  and  novel  methodologies,  this  thesis  demonstrates  the  importance  of  accounting  for  the  temporal  dynamics  of  malicious  network  infrastructure.  Specifically,  it  introduces  a  novel  methodology  that  accurately  identifies  historically  utilized  IP  infrastructure  from  domain  names  of  sophisticated  threats,  which  expands  the  publicly  reported  IP  knowledge  by  3.06  times.  It  also  showcases  how  the  temporal  analysis  of  malicious  network  infrastructure  can  help  threat  analysts  and  security  practitioners  better  understand  the  quantitative  distributions  of  the  network  interactions  of  the  stakeholders  (i.e.,  scanners,  security  vendors,  victims,  and  threat  actors).  More  precisely,  this  thesis  pinpoints  the  minimum  network  log  retention  window  for  uncovering  at  least  90%  of  the  infrastructure  of  sophisticated  attacks  down  to  25  months  and  characterizes  for  the  first  time  the  lifecycle  of  network  requests  into  malware-related  domain  names  from  the  upper  DNS  hierarchy.  These  insights  have  applicable  takeaways  for  log  retention  policies  for  network  data  and  victim  and  infrastructure  analysis  studies  using  DNS  datasets.
■590    ▼aSchool  code:  0078.
■650  4▼aMalware
■650  4▼aThreats
■650  4▼aScanners
■650  4▼aCybercrime
■650  4▼aURLs
■650  4▼aCriminology
■690    ▼a0543
■690    ▼a0627
■690    ▼a0501
■71020▼aGeorgia  Institute  of  Technology.
■7730  ▼tDissertations  Abstracts  International▼g87-05A.
■790    ▼a0078
■791    ▼aPh.D.
■792    ▼a2025
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17360267▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF18591 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.