论文标题
云作为攻击平台
Cloud as an Attack Platform
论文作者
论文摘要
我们提出了一项探索性研究,对$ 75 $安全专业人员和道德黑客的回应,以了解他们如何滥用云平台出于攻击目的。参与者是在Black Hat和Def Conforence招募的。我们以各种攻击方案向参与者介绍了他们,并要求他们解释在每种情况下发动攻击的步骤。研究了参与者的反应以了解攻击者的心理模型,这将提高我们对必要的安全控制和有关预防性行动的建议,以规避云对恶意活动的开发。我们观察到,在93.78%的回应中,参与者正在滥用云服务来建立其攻击环境并发动攻击。
We present an exploratory study of responses from $75$ security professionals and ethical hackers in order to understand how they abuse cloud platforms for attack purposes. The participants were recruited at the Black Hat and DEF CON conferences. We presented the participants' with various attack scenarios and asked them to explain the steps they would have carried out for launching the attack in each scenario. Participants' responses were studied to understand attackers' mental models, which would improve our understanding of necessary security controls and recommendations regarding precautionary actions to circumvent the exploitation of clouds for malicious activities. We observed that in 93.78% of the responses, participants are abusing cloud services to establish their attack environment and launch attacks.