Cloud-Based Push-Styled Mobile Botnets: A Case Study of Exploiting the Cloud to Device Messaging Service

被引:0
|
作者
Zhao, Shuang [1 ,2 ]
Lee, Patrick P. C. [3 ]
Lui, John C. S. [3 ]
Guan, Xiaohong [1 ]
Ma, Xiaobo [1 ]
Tao, Jing [1 ]
机构
[1] Xi An Jiao Tong Univ, Sch Elect & Informat Engn, Xian, Peoples R China
[2] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[3] Chinese Univ Hong Kong, Dept Comp Sci & Engn, Hong Kong, Hong Kong, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Given the popularity of smartphones and mobile devices, mobile botnets are becoming an emerging threat to users and network operators. We propose a new form of cloud-based push-styled mobile botnets that exploits today's push notification services as a means of command dissemination. To motivate its practicality, we present a new command and control (C&C) channel using Google's Cloud to Device Messaging (C2DM) service, and develop a C2DM botnet specifically for the Android platform. We present strategies to enhance its scalability to large botnet coverage and its resilience against service disruption. We prototype a C2DM botnet, and perform evaluation to show that the C2DM botnet is stealthy in generating heartbeat and command traffic, resource-efficient in bandwidth and power consumptions, and controllable in quickly delivering a command to all bots. We also discuss how one may deploy a C2DM botnet, and demonstrate its feasibility in launching an SMS-Spam-and-Click attack. Lastly, we discuss how to generalize the design to other platforms, such as iOS or Window-based systems, and recommend possible defense methods. Given the wide adoption of push notification services, we believe that this type of mobile botnets requires special attention from our community.
引用
收藏
页码:119 / 128
页数:10
相关论文
共 50 条
  • [41] The Design and Implementation of Cloud Service Based Customized Mobile Device Application System
    Tong, Zhu
    Zhuo, Gao
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION APPLICATIONS (ICCIA 2012), 2012, : 707 - 710
  • [42] Sporadic Cloud-Based Mobile Augmentation on the Top of a Virtualization Layer: A Case Study of Collaborative Downloads in VANETs
    Fernando Ordonez-Morales, Esteban
    Lopez-Nores, Martin
    Blanco-Fernandez, Yolanda
    Patricio Reinoso-Mendoza, Efren
    Fernando Bravo-Torres, Jack
    Victor Saians-Vazquez, Jose
    Juan Pazos-Arias, Jose
    Ramos-Cabrer, Manuel
    Gil-Solla, Alberto
    JOURNAL OF ADVANCED TRANSPORTATION, 2019, 2019
  • [43] Cloud-Based Cyber-Physical Robotic Mobile Fulfillment Systems: A Case Study of Collision Avoidance
    Keung, K. L.
    Lee, C. K. M.
    Ji, P.
    Ng, Kam K. H.
    IEEE ACCESS, 2020, 8 : 89318 - 89336
  • [44] Analysis of a cloud-based mobile device management solution on android phones: technological and organizational aspects
    Glowinski, Kamil
    Gossmann, Christian
    Struempf, Dominik
    SN APPLIED SCIENCES, 2020, 2 (01):
  • [45] Toward a cloud-based mobile device: Scriptable web applications as first-class citizens
    Mikkonen, Tommi
    Terho, Mikko
    Kuusipalo, Mikko
    Reijula, Pekka
    Salminen, Arto
    SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2012, 6 (04) : 341 - 349
  • [46] Toward a cloud-based mobile device: Scriptable web applications as first-class citizens
    Tommi Mikkonen
    Mikko Terho
    Mikko Kuusipalo
    Pekka Reijula
    Arto Salminen
    Service Oriented Computing and Applications, 2012, 6 (4) : 341 - 349
  • [47] Analysis of a cloud-based mobile device management solution on android phones: technological and organizational aspects
    Kamil Glowinski
    Christian Gossmann
    Dominik Strümpf
    SN Applied Sciences, 2020, 2
  • [48] A cloud-based production system for information and service integration: an internet of things case study on waste electronics
    Wang, Xi Vincent
    Wang, Lihui
    ENTERPRISE INFORMATION SYSTEMS, 2017, 11 (07) : 952 - 968
  • [49] A Fluctuation-Based Modelling Approach to Quantification of the Technical Debt on Mobile Cloud-Based Service Level
    Skourletopoulos, Georgios
    Mavromoustakis, Constandinos X.
    Mastorakis, George
    Rodrigues, Joel J. P. C.
    Chatzimisios, Periklis
    Batalla, Jordi Mongay
    2015 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2015,
  • [50] A Study of Factors Affecting Intention to Adopt a Cloud-Based Digital Signature Service
    Chong, Kyung Won
    Kim, Yong Seok
    Choi, Jeongil
    INFORMATION, 2021, 12 (02) : 1 - 15