Cloud-Based Push-Styled Mobile Botnets: A Case Study of Exploiting the Cloud to Device Messaging Service

被引:0
|
作者
Zhao, Shuang [1 ,2 ]
Lee, Patrick P. C. [3 ]
Lui, John C. S. [3 ]
Guan, Xiaohong [1 ]
Ma, Xiaobo [1 ]
Tao, Jing [1 ]
机构
[1] Xi An Jiao Tong Univ, Sch Elect & Informat Engn, Xian, Peoples R China
[2] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[3] Chinese Univ Hong Kong, Dept Comp Sci & Engn, Hong Kong, Hong Kong, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Given the popularity of smartphones and mobile devices, mobile botnets are becoming an emerging threat to users and network operators. We propose a new form of cloud-based push-styled mobile botnets that exploits today's push notification services as a means of command dissemination. To motivate its practicality, we present a new command and control (C&C) channel using Google's Cloud to Device Messaging (C2DM) service, and develop a C2DM botnet specifically for the Android platform. We present strategies to enhance its scalability to large botnet coverage and its resilience against service disruption. We prototype a C2DM botnet, and perform evaluation to show that the C2DM botnet is stealthy in generating heartbeat and command traffic, resource-efficient in bandwidth and power consumptions, and controllable in quickly delivering a command to all bots. We also discuss how one may deploy a C2DM botnet, and demonstrate its feasibility in launching an SMS-Spam-and-Click attack. Lastly, we discuss how to generalize the design to other platforms, such as iOS or Window-based systems, and recommend possible defense methods. Given the wide adoption of push notification services, we believe that this type of mobile botnets requires special attention from our community.
引用
收藏
页码:119 / 128
页数:10
相关论文
共 50 条
  • [1] Cloud-based Mobile Botnets Using Multiple Push Servers
    Chen, Wei
    Yin, Chengyu
    Zhou, Shiwen
    Yan, Xiaoshuang
    2015 SEVENTH INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS AND PROGRAMMING (PAAP), 2015, : 183 - 189
  • [2] Cloud-Based Mobile Testing as a Service
    Tao, Chuanqi
    Gao, Jerry
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2016, 26 (01) : 147 - 152
  • [3] Inspection of Hidden Dangers Based on Cloud Messaging Push Service
    Li, Ruixin
    Luo, Xiong
    IEEE 12TH INT CONF UBIQUITOUS INTELLIGENCE & COMP/IEEE 12TH INT CONF ADV & TRUSTED COMP/IEEE 15TH INT CONF SCALABLE COMP & COMMUN/IEEE INT CONF CLOUD & BIG DATA COMP/IEEE INT CONF INTERNET PEOPLE AND ASSOCIATED SYMPOSIA/WORKSHOPS, 2015, : 978 - 985
  • [4] Cloud-Based Infrastructure for Mobile Testing as a Service
    Tao, Chuanqi
    Gao, Jerry
    Li, Bixin
    2015 THIRD INTERNATIONAL CONFERENCE ON ADVANCED CLOUD AND BIG DATA, 2015, : 133 - 140
  • [5] A Case for Cloud-Based Mobile Search
    Yan Gao
    ZTE Communications, 2011, 9 (01) : 33 - 36
  • [6] Cloud-based or On-device: An Empirical Study of Mobile Deep Inference
    Guo, Tian
    2018 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2018), 2018, : 184 - 190
  • [7] DaaS: Cloud-based mobile Web service discovery
    Elgazzar, Khalid
    Hassanein, Hossam S.
    Martin, Patrick
    PERVASIVE AND MOBILE COMPUTING, 2014, 13 : 67 - 84
  • [8] Public Use of Mobile Medical Applications: A Case Study on Cloud-Based Medical Service of Taiwan
    Lu, Chen-Luan
    Yan, Yu-Hua
    NURSING INFORMATICS 2016: EHEALTH FOR ALL: EVERY LEVEL COLLABORATION - FROM PROJECT TO REALIZATION, 2016, 225 : 623 - 624
  • [9] Adaptive and Dynamic Service Composition for Cloud-Based Mobile Application
    Ramasamy, R. Kanesaraj
    Chua, Fang-Fang
    Haw, Su-Cheng
    ADVANCED COMPUTER AND COMMUNICATION ENGINEERING TECHNOLOGY, 2015, 315
  • [10] On building a cloud-based mobile testing infrastructure service system
    Tao, Chuanqi
    Gao, Jerry
    JOURNAL OF SYSTEMS AND SOFTWARE, 2017, 124 : 39 - 55