서브메뉴
검색
Towards Understanding the Lifecycle of Malicious Network Infrastructure
Towards Understanding the Lifecycle of Malicious Network Infrastructure
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20260202105331
- ISBN
- 9798263324865
- DDC
- 005.8
- 서명/저자
- Towards Understanding the Lifecycle of Malicious Network Infrastructure
- 발행사항
- [Sl] : Georgia Institute of Technology, 2025
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2025
- 형태사항
- 152 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 87-05, Section: A.
- 주기사항
- Advisor: Antonakakis, Manos;Keromytis, Angelos.
- 학위논문주기
- Thesis (Ph.D.)--Georgia Institute of Technology, 2025.
- 초록/해제
- 요약Network infrastructure is an important component of malicious cyber operations. From novice attacks conducted by script kiddies to highly sophisticated threats backed by nationstates, network infrastructure is being utilized for command and control, data exfiltration, malware hosting, and social engineering, among others. Over the years, while there have been several studies that have focused on detecting, blocking, and characterizing malicious infrastructure, the temporal dynamics of how this infrastructure changes over time and the characteristics of the stakeholders interacting with it have often been overlooked. This thesis shows that the temporal analysis of malicious infrastructure reveals network attributes that can characterize the stakeholders that interact with it. The systematic analysis of such network attributes can aid the accurate discovery of previously unreported malicious infrastructure and increase our awareness of the behaviors of the stakeholders that interact with it.Through longitudinal empirical studies and novel methodologies, this thesis demonstrates the importance of accounting for the temporal dynamics of malicious network infrastructure. Specifically, it introduces a novel methodology that accurately identifies historically utilized IP infrastructure from domain names of sophisticated threats, which expands the publicly reported IP knowledge by 3.06 times. It also showcases how the temporal analysis of malicious network infrastructure can help threat analysts and security practitioners better understand the quantitative distributions of the network interactions of the stakeholders (i.e., scanners, security vendors, victims, and threat actors). More precisely, this thesis pinpoints the minimum network log retention window for uncovering at least 90% of the infrastructure of sophisticated attacks down to 25 months and characterizes for the first time the lifecycle of network requests into malware-related domain names from the upper DNS hierarchy. These insights have applicable takeaways for log retention policies for network data and victim and infrastructure analysis studies using DNS datasets.
- 일반주제명
- Malware
- 일반주제명
- Threats
- 일반주제명
- Scanners
- 일반주제명
- Cybercrime
- 일반주제명
- URLs
- 일반주제명
- Criminology
- 기본자료저록
- Dissertations Abstracts International. 87-05A.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008260126s2025 us c eng d■001000017360267
■00520260202105331
■006m o d
■007cr#unu||||||||
■020 ▼a9798263324865
■035 ▼a(MiAaPQ)AAI32307950
■035 ▼a(MiAaPQ)GeorgiaTech78717
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a005.8
■1001 ▼aAvgetidis, Athanasios.
■24510▼aTowards Understanding the Lifecycle of Malicious Network Infrastructure
■260 ▼a[Sl]▼bGeorgia Institute of Technology▼c2025
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2025
■300 ▼a152 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 87-05, Section: A.
■500 ▼aAdvisor: Antonakakis, Manos;Keromytis, Angelos.
■5021 ▼aThesis (Ph.D.)--Georgia Institute of Technology, 2025.
■520 ▼aNetwork infrastructure is an important component of malicious cyber operations. From novice attacks conducted by script kiddies to highly sophisticated threats backed by nationstates, network infrastructure is being utilized for command and control, data exfiltration, malware hosting, and social engineering, among others. Over the years, while there have been several studies that have focused on detecting, blocking, and characterizing malicious infrastructure, the temporal dynamics of how this infrastructure changes over time and the characteristics of the stakeholders interacting with it have often been overlooked. This thesis shows that the temporal analysis of malicious infrastructure reveals network attributes that can characterize the stakeholders that interact with it. The systematic analysis of such network attributes can aid the accurate discovery of previously unreported malicious infrastructure and increase our awareness of the behaviors of the stakeholders that interact with it.Through longitudinal empirical studies and novel methodologies, this thesis demonstrates the importance of accounting for the temporal dynamics of malicious network infrastructure. Specifically, it introduces a novel methodology that accurately identifies historically utilized IP infrastructure from domain names of sophisticated threats, which expands the publicly reported IP knowledge by 3.06 times. It also showcases how the temporal analysis of malicious network infrastructure can help threat analysts and security practitioners better understand the quantitative distributions of the network interactions of the stakeholders (i.e., scanners, security vendors, victims, and threat actors). More precisely, this thesis pinpoints the minimum network log retention window for uncovering at least 90% of the infrastructure of sophisticated attacks down to 25 months and characterizes for the first time the lifecycle of network requests into malware-related domain names from the upper DNS hierarchy. These insights have applicable takeaways for log retention policies for network data and victim and infrastructure analysis studies using DNS datasets.
■590 ▼aSchool code: 0078.
■650 4▼aMalware
■650 4▼aThreats
■650 4▼aScanners
■650 4▼aCybercrime
■650 4▼aURLs
■650 4▼aCriminology
■690 ▼a0543
■690 ▼a0627
■690 ▼a0501
■71020▼aGeorgia Institute of Technology.
■7730 ▼tDissertations Abstracts International▼g87-05A.
■790 ▼a0078
■791 ▼aPh.D.
■792 ▼a2025
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17360267▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


