25
Booting the booters Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings [email protected] 1

[email protected] Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings [email protected]

  • Upload
    others

  • View
    8

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Booting the bootersBen Collier, Daniel R. Thomas, Richard Clayton,

Alice [email protected]

1

Page 2: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

The booter market is vulnerable● Interventions work (unusual)

○ Widespread arrests and takedowns○ Closure of Hackforums booter section○ Advertising

● Target server managers○ Have mid-level technical (administrative) skills○ Work is tedious and low-status

2

Page 3: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

3

Page 4: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Booter services scale DDoS users●

●●

4

Page 5: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

5

Page 6: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

6

Page 7: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

7

Someone you don’t like

Page 8: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Booters: Dispersed but advertised●

●●●

8

Page 9: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Collection 1: UDP-reflection attacks from honeypots● Median 65 nodes since 2014● Hopscotch emulates abused protocols: QOTD, CHARGEN,

DNS, NTP, SSDP, SQLMon, Portmap, mDNS, LDAP● Sniffer records all resulting UDP traffic● (try to) Only reply to black hat scanners● Attack: Flow to an IP(prefix) where more than 5 packets

received by one sensor

Ethics: Absorb attack traffic, don’t reply to white hat scanners

9

Daniel R. Thomas, Richard Clayton, and Alastair R. Beresford. 2017. 1000 days of UDP amplification DDoS attacks. In APWG Symposium on Electronic Crime Research (eCrime). IEEE, (Apr. 2017).

Page 10: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

10

Page 11: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Collection 2: Booter self-reports (are reliable)● Collected from booter websites which report running total● Covers 75% of active booters over 18 month period● Source code and leaked databases show generally

accurate (bad data excluded)● Heteroskedasticity and skewness kurtosis tests indicate

not faked● Correlate with Collection 1 and with interventions.

11

Page 12: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

12

Page 13: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

13

PRESENTER SWITCH

Page 14: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Intervening is hard●●●●●

14

Page 15: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

●●●●

15

Page 16: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

16

Page 17: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

17

Example takedown - FBI operation● 20th December 2018● Distributed Denial of Service as a Services (booters /

stressers) targetted● 3 arrests● 15 domains seized, 7 booters

Page 18: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Modelling● Negative binomial regression● Time series of weekly totals and by country● ‘Intervention’ variables for all big drops, keep significant

ones

18

Page 19: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

19

Page 20: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

●●

20

Page 21: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

21

Page 22: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Results 2: self-reported (my favourite slide)

22

Webstresser arrest

FBI takedowns

Page 23: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Analysis● Less resilient than other kinds of cybercrime (we think)● Single arrests and sentencing do little● But hitting the infrastructure and messaging campaigns

work

23

Page 24: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

Why: Qualitative results● Interviews and scraping chat channels● Booting is rubbish! Low cultural capital● High user turnover - so if you can stop people getting involved, big

effect● Lots of centralisation reselling makes the market brittle to

infrastructural intervention● Depends on a relatively small number of server managers● Who have a boring and unrewarding job, so easy to dissuade ● Especially when you make their job even more annoying by messing

with the infrastructure!24

Page 25: Firstname.Lastname@cl.cam.ac.uk Booting the booters Alice … · 2019. 11. 11. · Ben Collier, Daniel R. Thomas, Richard Clayton, Alice Hutchings Firstname.Lastname@cl.cam.ac.uk

● USE OUR DATA● Talk to us about future work● [email protected]● @johnnyhistone● [email protected]● @DanielRThomas24● https://www.cambridgecybercrime.uk/process.html

25