Skip to main content
QUICK REVIEW

[论文解读] Honey Sheets: What Happens to Leaked Google Spreadsheets?

Martin Lazarov, Jeremiah Onaolapo|arXiv (Cornell University)|Jul 4, 2016
Spam and Phishing Detection参考文献 12被引用 7
一句话总结

本文提出了 Honey Sheets 系統,透過在偽裝的 Google Spreadsheets 中嵌入追蹤連結,監控雲端文件洩漏時駭客的行為。作者將這些蜜罐試算表的連結張貼於貼文網站,觀察到共 165 次存取、28 次修改行為(包含刪除偽造資料與破壞),以及來自 35 個國家的 174 次混淆連結點擊,揭露了攻擊者如資料篡改與破壞等行動模式。

ABSTRACT

Cloud-based documents are inherently valuable, due to the volume and nature of sensitive personal and business content stored in them. Despite the importance of such documents to Internet users, there are still large gaps in the understanding of what cybercriminals do when they illicitly get access to them by for example compromising the account credentials they are associated with. In this paper, we present a system able to monitor user activity on Google spreadsheets. We populated 5 Google spreadsheets with fake bank account details and fake funds transfer links. Each spreadsheet was configured to report details of accesses and clicks on links back to us. To study how people interact with these spreadsheets in case they are leaked, we posted unique links pointing to the spreadsheets on a popular paste site. We then monitored activity in the accounts for 72 days, and observed 165 accesses in total. We were able to observe interesting modifications to these spreadsheets performed by illicit accesses. For instance, we observed deletion of some fake bank account information, in addition to insults and warnings that some visitors entered in some of the spreadsheets. Our preliminary results show that our system can be used to shed light on cybercriminal behavior with regards to leaked online documents.

研究动机与目标

  • 了解駭客如何與被竊取的雲端文件(特別是 Google Spreadsheets)互動。
  • 開發一項能即時監控受損文件上非法存取與操作行為的系統。
  • 研究透過洩漏憑證取得敏感文件存取權之攻擊者的行為。
  • 識別攻擊者行為模式,例如其目標內容與修改方式。
  • 為研究人員提供一種可擴展的方法,以研究雲端文件被入侵情境下的駭客作戰模式。

提出的方法

  • 部署 5 個預先填入偽造財務資料與混淆追蹤網域連結的蜜罐 Google Spreadsheets。
  • 使用 Google Apps Script 記錄使用者互動,包括檔案開啟、內容修改與連結點擊,並記錄 IP 位址與 HTTP 標頭。
  • 設定試算表為可公開編輯,透過共用連結模擬真實世界中的洩漏情境。
  • 將獨特的試算表連結張貼於知名貼文網站,模擬真實憑證洩漏情境。
  • 監控 72 天內的所有活動,記錄所有存取事件與嵌入連結的互動。
  • 收集並分析存取模式、修改行為與點擊行為的紀錄,以推斷攻擊者行為。

实验结果

研究问题

  • RQ1攻擊者在竊取的雲端文件上執行哪些操作?我們能否根據這些操作識別出不同類型的駭客?
  • RQ2攻擊者對文件中的哪類內容更感興趣或互動更頻繁?
  • RQ3攻擊者在非法取得存取權後,如何修改或破壞文件?
  • RQ4與洩漏之雲端文件互動的攻擊者在地理分布上有何特徵?
  • RQ5嵌入的追蹤連結在真實世界文件洩漏情境中,捕捉攻擊者行為的成效如何?

主要发现

  • 在 72 天內共記錄到 165 次獨特存取,並在蜜罐試算表上觀察到 28 次修改事件。
  • 攻擊者刪除偽造的銀行帳戶資訊、輸入侮辱性文字,並破壞試算表,使其無法使用。
  • 共記錄到 174 次嵌入混淆連結的點擊,來自 35 個不同國家。
  • 部分攻擊者擴展試算表的欄位,顯示其試圖更輕鬆地檢視或提取資料。
  • 有一名攻擊者將追蹤連結替換為 C++ 程式碼片段,顯示可能存在程式碼注入或破壞行為。
  • 系統成功捕捉到即時互動,證明其在研究受損雲端文件上駭客行為方面的可行性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。