[论文解读] Evaluating the Impact of AbuseHUB on Botnet Mitigation
本研究通过分析荷兰成员与非成员ISP的僵尸网络感染率,并与全球同行进行比较,评估了由荷兰ISP主导的滥用数据共享平台AbuseHUB的效果。利用多个数据源的归一化感染指标,研究发现AbuseHUB成员的感染水平显著低于非成员及全球顶级ISP,证明了通过协调数据共享和自动化清理,该平台在提升僵尸网络缓解效果方面具有显著成效。
This documents presents the final report of a two-year project to evaluate the impact of AbuseHUB, a Dutch clearinghouse for acquiring and processing abuse data on infected machines. The report was commissioned by the Netherlands Ministry of Economic Affairs, a co-funder of the development of AbuseHUB. AbuseHUB is the initiative of 9 Internet Service Providers, SIDN (the registry for the .nl top-level domain) and Surfnet (the national research and education network operator). The key objective of AbuseHUB is to improve the mitigation of botnets by its members. We set out to assess whether this objective is being reached by analyzing malware infection levels in the networks of AbuseHUB members and comparing them to those of other Internet Service Providers (ISPs). Since AbuseHUB members together comprise over 90 percent of the broadband market in the Netherlands, it also makes sense to compare how the country as a whole has performed compared to other countries. This report complements the baseline measurement report produced in December 2013 and the interim report from March 2015. We are using the same data sources as in the interim report, which is an expanded set compared to the earlier baseline report and to our 2011 study into botnet mitigation in the Netherlands.
研究动机与目标
- 评估AbuseHUB是否显著降低了其成员ISP的僵尸网络感染率,相较于非成员ISP。
- 将荷兰的整体僵尸网络表现与其它国家进行比较,以评估AbuseHUB对国家层面的影响。
- 分析AbuseHUB成员ISP之间的表现差异,以识别最佳实践。
- 评估其他国家中反僵尸网络计划(ABIs)的有效性。
- 为通过数据共享和政策激励扩大滥用缓解措施提供基于证据的建议。
提出的方法
- 从全球及荷兰本地数据源(包括Shadowserver、Spamhaus和蜜罐数据)收集并分析恶意软件感染数据。
- 通过地理定位和ASN解析将受感染IP地址映射至ISP,然后按用户数量对感染数量进行归一化处理,以实现公平比较。
- 基于每百万名订阅用户平均每日唯一受感染IP数量对ISP和国家进行排名,以考虑网络规模差异。
- 利用2014–2015年感染趋势的时间序列分析,将AbuseHUB成员与非成员及全球ISP进行比较。
- 识别荷兰境内感染最严重的10家非成员ISP,以评估非成员身份对感染水平的影响。
- 使用散点图和归一化指标可视化不同ISP及僵尸网络类型之间的表现差异。
实验结果
研究问题
- RQ1荷兰的AbuseHUB成员ISP是否表现出显著低于非成员ISP的僵尸网络感染率?
- RQ2在僵尸网络感染水平方面,荷兰与其它国家相比如何,特别是与实施反僵尸网络计划(ABIs)的国家相比?
- RQ3各AbuseHUB成员ISP的表现如何比较,哪些ISP展现出最有效的缓解措施?
- RQ4数据共享和自动化清理对降低荷兰ISP市场整体感染率产生了多大影响?
- RQ5非成员ISP在整体感染水平中贡献有多大,能否通过激励措施促使他们加入缓解行动?
主要发现
- AbuseHUB成员的感染率显著低于非成员,在2015年,其每百万名订阅用户平均每日受感染IP数量低了30%至50%。
- 荷兰在全球范围内位列僵尸网络感染水平最低的前10个国家,表现优于大多数同行,包括一些拥有正式反僵尸网络计划的国家。
- 荷兰感染最严重的10家非成员ISP的感染率最高可达AbuseHUB成员平均水平的5倍。
- 在AbuseHUB成员中,表现差异显著:部分ISP的感染率低于每百万名订阅用户10个受感染IP,而另一些则仍高于50个。
- 本研究未发现其他国家的ABIs导致优于荷兰模式的结果,表明AbuseHUB的成效并非仅源于国家政策。
- 集中式清理工具和数据共享显著降低了客户支持成本并提升了缓解效率,德国的botfrei.de模式已证明了这一点。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。