Technical analysis: smart hardware worms threaten Internet Security

Source: Internet
Author: User

Technical analysis: smart hardware worms threaten Internet Security

Reference:
 

The global Internet DNS traffic has been abnormal since the previous day (January 1, December 10. The cloud dike Team (DamDDoS) Quickly participated in analysis and disposal. The attack continued since the morning of June December 10. For the longest DNS DDoS attack in recent years, the maximum traffic detected is nearly 0.1 billion Qps (about 76.38 Gbps)

Tracking:

In December 10, during a DNS exception and Failure Period, the partner of the 360 Network Attack and Defense lab was also following up on this issue. Previously, go to * .arkhamnetwork.org; * .arkhamnetwork.com (to attack the authoritative Domain Name Server of a game service provider, and finally parse the content fraud. ddos. go. away, surrender) 360 of recursive DNS Cache attack traffic is about QPS,The attack method is to initiate a resolution request to query random prefix domain names, resulting in a denial of service for Recursive services.

It is based on the 360 big data security analysis visualization platform that finds a BOT terminal to resolve domain names. This attack feature is very obvious, and the attack method is also very crude.

The following figure shows more than * .arkhamnetwork.org; * .arkhamnetwork.com under a Denial-of-Service attack. The two main DNS servers are ns11.dnpresseeasy.com and ns12.dnpresseeasy.com. Many of these bots, such as IP: 167.114.25.179, have initiated many DNS Denial-of-Service attack requests for * .arkhamnetwork.org. Two nameservers are rejected.

 

In-depth analysis shows that most of these IP addresses are routers, smart cameras, and other devices.At first, attackers obtained SYSTEM privileges by executing these remote commands or using weak passwords. Then Implant the worm program. After the script runs, the network activity of the worm is constantly scanning port 23 of any C segment, and using weak passwords to capture more smart hardware devices, increase the number of points to generate larger attack traffic.

Locate the process file that calls the network activity through the network activity as follows. The worm generates many new process files that contain the commands executed by the process.

After the worm program is executed, malicious code with random file names will be generated in the specified directory and automatically deleted after running.

Fortunately, we found some undeleted malicious samples. So we can download the program and analyze it.

 

First, it is determined that these malicious files are ELF executable files, not script files.

We conduct static analysis on the sample file under IDA to see some task commands of the worm program and the address of the C2 server. The IP address of the C2 server shows the status of the smart hardware. Currently, the SLEEP And Dildos statuses are analyzed.

Based on the key information obtained after reverse analysis, further evidence of the state of the smart hardware worm is found, showing that the smart hardware is in Sleeping state.

When you enter the Sleeping status, this terminal is only connected to the C2 server (23.227.173.210), and does not execute any scan and infection tasks or perform DOS attacks.

 

Through the analysis of this smart hardware program, we can summarize the ways in which the smart hardware worm is infected. First, attackers can exploit the smart hardware vulnerability to obtain root privileges and execute the worm code. The C2 server waits for the smart hardware to go online. By default, the smart hardware infected with the worm will automatically scan and discover other smart hardware, and automatically exploit the vulnerability to infect the target with the worm program. Another State of the control program is Sleeping, which is to maintain the connection with the C2 server. Wait for the command to be issued, and no network activity is ongoing. The last step is to initiate an attack in the dildos status. According to the results of the current static analysis, there are several statuses. It is not ruled out that there will be more variants in the future.

Hazards

According to the data of the cloud bank, in December 10, the maximum Traffic Detected for attacks was nearly 0.1 billion Qps. (about 76.38 Gbps) combined with some foreign news about the attack, it is an attack that uses more than 1000 terminals. This number is already terrible. If 10000 of these smart hardware devices are infected and attacked, the traffic will reach about GB. What's more, the current smart cameras, router vulnerabilities, and smart sockets emerge one after another, and the future shipments also multiply. When intelligent hardware reaches a magnitude, its own security problems will pose a great security threat to the Internet. In fact, this is to extend the network battlefield to the field of intelligent hardware.

Preventive Measures

It is difficult to prevent such malicious programs. Most of them reside in the smart hardware firmware system, and the firmware does not have the environment on which the malicious programs depend. In addition, many users do not care about these devices after completing the initial configuration, which increases the difficulty of detection and removal.

1. Modify the default password of your smart camera, router, and other hardware. Follow the updates officially released. 2. vendors need to strengthen the firmware security audit and evaluate the smart hardware to ensure that there is no information security problem in the smart hardware. Pay attention to the security testing results and vulnerabilities of smart hardware at home and abroad. Patch a new vulnerability in time. 3. Relevant departments, operators, and security companies should monitor these bots in an all-round way. If a large number of abnormal attacks are initiated, traffic cleaning should be performed from the operator level. Periodically sample and analyze changes to malicious versions of a BOT. Develop related killing scripts.

 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.