| 講演抄録/キーワード |
| 講演名 |
2025-03-06 12:15
Linking IoT Attacks to Cybercrime-as-a-Service Offerings Using LLM and DNS Data ○Qingxin Mao(YNU)・Yin Minn Pa Pa・Rui Tanabe・Katsunari Yoshioka(IAS/YNU) ICSS2024-75 |
| 抄録 |
(和) |
(まだ登録されていません) |
| (英) |
Cyberattack monitoring systems, such as honeypots, typically focus on observing the technical aspects of attacks rather than identifying the attackers themselves. However, linking attacks to Cybercrime-as-a-Service (CaaS) offerings is critical for developing more effective countermeasures and understanding their strategies. This study investigates the hypothesis that attackers reuse their IP addresses not only for attacks but also for other cybercrime-related activities, such as offering CaaS. Using over 20,000 IP addresses associated with IoT-related attacks (e.g., command-and-control servers, malware download servers, and malware loaders), we identified related domains through DNSDB queries. Domain names indicative of cybercrime activities were then extracted using a large language model (LLM). This process uncovered over 1,838 domains containing keywords such as “ddos,” “stresser,” and “bot.” Further analysis of these domains revealed their use in offering DDoS-as-a-Service, selling stolen data, and distributing botnet source code. Our findings demonstrate the potential of linking IoT attacks to CaaS through their infrastructure, offering new insights into cybercriminal operations and enhancing the effectiveness of cybersecurity measures. |
| キーワード |
(和) |
/ / / / / / / |
| (英) |
IoT Botnet / CaaS / Booter / Stresser / DDoS / / / |
| 文献情報 |
信学技報, vol. 124, no. 422, ICSS2024-75, pp. 47-54, 2025年3月. |
| 資料番号 |
ICSS2024-75 |
| 発行日 |
2025-02-27 (ICSS) |
| ISSN |
Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
ICSS2024-75 |
|