论文标题

hackerscope:大规模黑客在线生态系统的动态

HackerScope: The Dynamics of a Massive Hacker Online Ecosystem

论文作者

Islam, Risul, Rokon, Md Omar Faruk, Darki, Ahmad, Faloutsos, Michalis

论文摘要

恶意软件的作者并没有像人们那样隐藏:他们有可见的在线足迹。除在线论坛外,此足迹还出现在软件开发平台中,作者创建了可公开访问的恶意软件存储库来共享和协作。除了最近的一些努力之外,这个社区的存在和动态受到了惊人的关注。我们工作的目的是分析这个黑客生态系统,以:(a)了解他们的协作模式,以及(b)识别并介绍其最有影响力的作者。我们开发了hackerscope,这是一种用于分析该黑客生态系统动态的系统方法。利用目标数据收集,我们对GitHub上的7389名恶意软件存储库作者进行了广泛的研究,我们将其与他们在四个安全论坛上的活动结合使用。从建模的角度来看,我们使用三个网络表示研究生态系统:(a)作者 - 作者网络,(b)作者重复网络和(c)跨平台Egonets。我们的分析导致以下主要观察结果:(a)随着每年两年的新恶意软件作者的数量每年两年的数量,生态系统的增长速度正在加速,(b)它是高度协作的,比其他Github的作者更重要,并且(C)它包括有影响力的和专业的黑客。我们发现30位作者在GitHub和我们的安全论坛上维护了一个在线“品牌”。我们的研究是使用公共在线信息了解恶意黑客社区的重要一步。

Authors of malicious software are not hiding as much as one would assume: they have a visible online footprint. Apart from online forums, this footprint appears in software development platforms, where authors create publicly-accessible malware repositories to share and collaborate. With the exception of a few recent efforts, the existence and the dynamics of this community has received surprisingly limited attention. The goal of our work is to analyze this ecosystem of hackers in order to: (a) understand their collaborative patterns, and (b) identify and profile its most influential authors. We develop HackerScope, a systematic approach for analyzing the dynamics of this hacker ecosystem. Leveraging our targeted data collection, we conduct an extensive study of 7389 authors of malware repositories on GitHub, which we combine with their activity on four security forums. From a modeling point of view, we study the ecosystem using three network representations: (a) the author-author network, (b) the author-repository network, and (c) cross-platform egonets. Our analysis leads to the following key observations: (a) the ecosystem is growing at an accelerating rate as the number of new malware authors per year triples every 2 years, (b) it is highly collaborative, more so than the rest of GitHub authors, and (c) it includes influential and professional hackers. We find 30 authors maintain an online "brand" across GitHub and our security forums. Our study is a significant step towards using public online information for understanding the malicious hacker community.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源