论文标题

模仿-AS-A-Service:表征新兴的犯罪基础设施以进行大规模模仿

Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at Scale

论文作者

Campobasso, Michele, Allodi, Luca

论文摘要

在本文中,我们提供了新兴的犯罪基础设施的证据,可以大规模采用模仿攻击。 Pymenation-As-As-As-Service(IMPAAS)允许攻击者系统地收集和强制执行用户配置文件(由用户凭据,cookie,设备和行为指纹以及其他元数据组成),以绕开基于风险的身份验证系统,并有效地绕过多因素真实勘探机制。我们介绍了IMPAAS模型,并通过分析一个大型,仅邀请的俄罗斯Impaas平台的操作,以超过260'000美元的互联网用户的互联网用户提供用户配置文件。我们的发现表明,IMPAAS模型正在增长,并提供了系统地逃避多个平台的身份验证控制所需的机制,同时为攻击者提供了可靠,最新和半自动化的环境,从而使目标选择和用户对互联网用户的规模进行冒险。

In this paper we provide evidence of an emerging criminal infrastructure enabling impersonation attacks at scale. Impersonation-as-a-Service (ImpaaS) allows attackers to systematically collect and enforce user profiles (consisting of user credentials, cookies, device and behavioural fingerprints, and other metadata) to circumvent risk-based authentication system and effectively bypass multi-factor authentication mechanisms. We present the ImpaaS model and evaluate its implementation by analysing the operation of a large, invite-only, Russian ImpaaS platform providing user profiles for more than $260'000$ Internet users worldwide. Our findings suggest that the ImpaaS model is growing, and provides the mechanisms needed to systematically evade authentication controls across multiple platforms, while providing attackers with a reliable, up-to-date, and semi-automated environment enabling target selection and user impersonation against Internet users as scale.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源