[论文解读] An Information-Theoretical View of Network-Aware Malware Attacks
本文提出了一种信息论框架,通过使用Rényi熵量化非均匀脆弱主机分布的影响,分析网络感知型恶意软件的传播。结果表明,网络感知型恶意软件的感染速率可比随机扫描器快近非均匀性因子;当脆弱主机仍聚集时,主机级防护和IPv6等防御措施的抵抗能力有限。
This work investigates three aspects: (a) a network vulnerability as the non-uniform vulnerable-host distribution, (b) threats, i.e., intelligent malwares that exploit such a vulnerability, and (c) defense, i.e., challenges for fighting the threats. We first study five large data sets and observe consistent clustered vulnerable-host distributions. We then present a new metric, referred to as the non-uniformity factor, which quantifies the unevenness of a vulnerable-host distribution. This metric is essentially the Renyi information entropy and better characterizes the non-uniformity of a distribution than the Shannon entropy. Next, we analyze the propagation speed of network-aware malwares in view of information theory. In particular, we draw a relationship between Renyi entropies and randomized epidemic malware-scanning algorithms. We find that the infection rates of malware-scanning methods are characterized by the Renyi entropies that relate to the information bits in a non-unform vulnerable-host distribution extracted by a randomized scanning algorithm. Meanwhile, we show that a representative network-aware malware can increase the spreading speed by exactly or nearly a non-uniformity factor when compared to a random-scanning malware at an early stage of malware propagation. This quantifies that how much more rapidly the Internet can be infected at the early stage when a malware exploits an uneven vulnerable-host distribution as a network-wide vulnerability. Furthermore, we analyze the effectiveness of defense strategies on the spread of network-aware malwares. Our results demonstrate that counteracting network-aware malwares is a significant challenge for the strategies that include host-based defense and IPv6.
研究动机与目标
- 理解脆弱主机非均匀分布如何造成可被利用的网络漏洞。
- 利用信息论量化脆弱主机分布不均匀性与恶意软件传播速度之间的关系。
- 评估常见防御策略(如主机级防护和IPv6)对网络感知型恶意软件的有效性。
- 证明网络感知型恶意软件可通过利用分布非均匀性实现接近最优的感染速率。
提出的方法
- 非均匀性因子定义为二阶Rényi熵,相比Shannon熵,能更有效地量化脆弱主机分布的不均匀性。
- 本文将恶意软件扫描建模为随机流行病过程,并将感染速率与不同阶数的Rényi熵相关联。
- 推导出解析表达式,将网络感知型恶意软件的感染速率与定位脆弱主机的不确定性(Rényi熵)联系起来。
- 利用五组大规模测量的实证数据计算非均匀性因子,结果在多种网络和应用中均显示一致的高值。
- 通过将局部扫描与修改后的顺序扫描的感染速率与随机扫描进行比较,验证了模型,结果表明实现了接近理想的性能提升。
- 通过外推子网感染速率分析IPv6对恶意软件传播的影响,结果表明:若脆弱主机仍聚集,IPv6不会从根本上减缓网络感知型恶意软件的传播。
实验结果
研究问题
- RQ1如何量化脆弱主机分布的不均匀性,以反映其对恶意软件传播的影响?
- RQ2网络感知型恶意软件在感染速度方面相比随机扫描型恶意软件能提升多少?
- RQ3不同随机扫描算法与Rényi熵等信息论度量之间有何关系?
- RQ4主机级防护或IPv6部署能否有效缓解网络感知型恶意软件的威胁?
- RQ5在利用非均匀脆弱主机分布时,恶意软件感染速度的理论上限是什么?
主要发现
- 基于二阶Rényi熵的非均匀性因子在五组实证数据集中始终显示高值,表明脆弱主机存在显著聚集现象。
- 在传播初期,网络感知型恶意软件相比随机扫描型恶意软件,其感染速率可提高近非均匀性因子。
- 局部扫描与修改后的顺序扫描的感染速率接近最优重要性扫描的水平,证明其在利用分布非均匀性方面接近最优。
- 在IPv6中,/32智能扫描器的感染速率估计为每秒2.2×10⁻³,高于IPv4中Code Red v2蠕虫的感染速率(5×10⁻⁴),表明若聚集持续存在,IPv6不会从根本上减缓此类威胁。
- 主机级防护需近乎完全部署才能有效,若脆弱主机仍聚集,IPv6提供的抵抗能力有限,使得网络感知型恶意软件在IPv6中可能成为潜在的零日威胁。
- 信息论框架成功将从脆弱主机分布中提取的信息比特与恶意软件的实际传播速度联系起来。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。