论文标题
零僵尸网络:一种观察 - 围场的方法
Zero Botnets: An Observe-Pursue-Counter Approach
论文作者
论文摘要
对抗性互联网机器人(僵尸网络)代表着对互联网安全使用和稳定性的日益严重的威胁。僵尸网络可以在推出对手侦察(扫描和网络钓鱼),影响力(投票)和融资运营(勒索软件,市场操纵,拒绝服务,垃圾邮件和AD点击欺诈)中发挥作用,同时肥胖量身定制的战术操作。以零的理想目标减少互联网上的僵尸网络的存在是镀锌政策行动的有力愿景。设定全球目标,鼓励国际合作,为改善网络创造激励措施,并为僵尸网络撤下的支持实体提供支持实体,这是可以促进这一目标的几项政策。这些政策提出了有关适当权威/访问权限的重大问题,这些问题无法摘要回答。系统分析已在其他领域中广泛使用,以实现足够的详细信息,以使这些问题以具体的术语来解决。分析了使用观察 - 赶式互动体系结构击败僵尸网络,确认了技术可行性,并且当局/访问问题被显着缩小。推荐的下一步包括:支持国际僵尸网络撤销社区,扩大网络观测站,增强基础网络科学的规模,进行详细的系统分析以及制定适当的政策框架。
Adversarial Internet robots (botnets) represent a growing threat to the safe use and stability of the Internet. Botnets can play a role in launching adversary reconnaissance (scanning and phishing), influence operations (upvoting), and financing operations (ransomware, market manipulation, denial of service, spamming, and ad click fraud) while obfuscating tailored tactical operations. Reducing the presence of botnets on the Internet, with the aspirational target of zero, is a powerful vision for galvanizing policy action. Setting a global goal, encouraging international cooperation, creating incentives for improving networks, and supporting entities for botnet takedowns are among several policies that could advance this goal. These policies raise significant questions regarding proper authorities/access that cannot be answered in the abstract. Systems analysis has been widely used in other domains to achieve sufficient detail to enable these questions to be dealt with in concrete terms. Defeating botnets using an observe-pursue-counter architecture is analyzed, the technical feasibility is affirmed, and the authorities/access questions are significantly narrowed. Recommended next steps include: supporting the international botnet takedown community, expanding network observatories, enhancing the underlying network science at scale, conducting detailed systems analysis, and developing appropriate policy frameworks.