Online Gaming and the Growing Impact of China DDoS - David Liebenberg

Preview:

Citation preview

David Liebenberg CiscoTalos

Online Gaming and the Growing Impact of China

DDoS

Agenda

1. OnlinegaminginChina

2. TheDDoSa5ackindustryanditsconnec<ontoonlinegaming

3. Casestudy:SSHPsychosandChinaZ

4.  IndicatorsthatDDoSa5acker/malwareisconnectedtoonlinegaming

5. ConclusionsandQ&A

Online Gaming Industry

Top10OnlineGamesinChina

Pirated Game Industry

•  Piratedgameserver=sifu, 私服

•  Profitabilityandcrowdedmarketplacecreatefiercecompe<<on

•  Bo5omline:bigbusinesswithli5leethicalrestraint

DDoS AAacks Take out Rivals

How It Works:

ToolDevelopers

A5ackerRepresenta<vesGamerA GamerB

BotnetOwners

Tool Developers

•  ManyChineseDDoStoolscanbedownloadedforfree

•  Specializedtoolscostmoneyandareproducedbydedicatedgroups

PlaHorm Rentals

RepresentaIves/AAackers

Case Study Conclusions

Collateral Damage

•  AWen’sPu5yDebacle

•  Takedownof.cn

•  KnightsA5ackingGroup(骑士攻击小组)

Domain Indicators

•  Domainnameswiththefollowingle5ercombina<onsfollowedorprecededbyaseriesofnumbersindicateaconnec<ontoonlinegaming:•  “gm”–Gamemaster•  “my”–Moyu•  “sf”–Sifu•  “45”–Sifu•  “xa”–Xiaoao•  “pk”–Playerkill•  “cf”–Crossfire•  999–999brand•  3322.org–ChineseDDNSthathostspiratedgames•  F3322.org–ChineseDDNSthathostspiratedgames

Chinese Characters

•  私服–Piratedgameserver•  游戏–Games•  接c单–AcceptCCa5acks(Layer7a5acks)•  接d单–AcceptDDoSa5acks•  登录器–Registra<onsoeware•  在线充值 –Replenishyouraccountonline•  抓鸡–Buildabotnet•  鸡肉–Botnet•  传奇–Legendgames•  魔域–Moyu•  火线–Crossfire•  流量 –Traffic•  攻击 –A5ack

Images to Watch:

Gamename Dateposted Wherehosted

Servername

Conclusions

•  TheonlinegamingindustryinChinaisconnectedtoDDoSa5acks

•  ThereareavarietyofDDoSgroups,offeringa5ackingservicesorsoeware

•  Hackerforumsandsocialmediacanbeleveragedforinforma<ononDDoSac<vity

•  Language-capableanalystsaddvaluetoinves<ga<ons

QuesIons: dliebenb@cisco.com

Recommended