命令与控制:理解、拒绝与检测——恶意软件 C2 技术、检测及防御综述
密码学与安全
2015-06-23 v2
摘要
在本综述中,我们首先简要回顾网络攻击的现状,强调近期此类攻击在执行方式和动机上的重大变化。随后,我们调查恶意软件命令与控制 (C2) 建立的机制:全面回顾攻击者用于建立此类通道并向受攻击方及其使用的安全工具隐藏其存在的技术。接着,我们转向问题的防御侧,回顾已提出的用于检测和破坏 C2 通道的方法。我们将这些技术映射到广泛采用的安全控制措施上,强调当前最佳实践中的差距或局限性(以及成功案例)。
引用
@article{arxiv.1408.1136,
title = {Command & Control: Understanding, Denying and Detecting - A review of malware C2 techniques, detection and defences},
author = {Joseph Gardiner and Marco Cova and Shishir Nagaraja},
journal= {arXiv preprint arXiv:1408.1136},
year = {2015}
}
备注
Work commissioned by CPNI, available at c2report.org. 38 pages. Listing abstract compressed from version appearing in report