Geolocalization of proxied services and its application to fast-flux hidden servers

Claude Castelluccia 1 Mohamed Ali Kaafar 1, * P. Manils D. Perito
* Auteur correspondant
1 PLANETE - Protocols and applications for the Internet
Inria Grenoble - Rhône-Alpes, CRISAM - Inria Sophia Antipolis - Méditerranée
Abstract : Fast-flux is a redirection technique used by cyber-criminals to hide the actual location of malicious servers. Its purpose is to evade identification and prevent or, at least delay, the shutdown of these illegal servers by law enforcement. This paper proposes a framework to geolocalize fast-flux servers, that is, to determine the physical location of the fast-flux networks roots (mothership servers) based on network measurements. We performed an extensive set of measurements on PlanetLab in order to validate and evaluate the performance of our method in a controlled environment. These experimentations showed that, with our framework, fast-flux servers can be localized with similar mean distance errors than non-hidden servers, i.e. approximately 100 km. In the light of these very promising results, we also applied our scheme to several active fast-flux servers and estimated their geographic locations, providing then statistics on the locations of "in the wild" fast-flux services.
Type de document :
Communication dans un congrès
Proceedings of the 9th ACM SIGCOMM conference on Internet measurement conference (IMC), Nov 2009, Chicago, United States. pp.184--189, 2009, 〈10.1145/1644893.1644915〉
Liste complète des métadonnées

https://hal.inria.fr/hal-00748235
Contributeur : Mohamed Ali Kaafar <>
Soumis le : lundi 5 novembre 2012 - 11:03:46
Dernière modification le : mercredi 11 avril 2018 - 01:53:44

Lien texte intégral

Identifiants

Collections

Citation

Claude Castelluccia, Mohamed Ali Kaafar, P. Manils, D. Perito. Geolocalization of proxied services and its application to fast-flux hidden servers. Proceedings of the 9th ACM SIGCOMM conference on Internet measurement conference (IMC), Nov 2009, Chicago, United States. pp.184--189, 2009, 〈10.1145/1644893.1644915〉. 〈hal-00748235〉

Partager

Métriques

Consultations de la notice

117