Decoy I/O on computers in production is designed to redirect malware towards phantom devices, where malware are intercepted and hence are immediately detected, pinpointed, and possibly controlled and leveraged against the threat actors. On their part, malware seek inconsistencies in their targets to detect decoys and avoid falling into a trap, possibly before it is too late for them. In this paper we explore modeling and simulation based on the queueing network formalism to provide decoy network interface cards and their associated network targets with an infallible timing consistency. We propose a practical approach that integrates the findings of modeling and simulation into the operating system kernel, and thus creates a usable source of timing consistency for network decoys. We implemented this work within the code of a decoy Object Linking and Embedding (OLE) for Process Control (OPC) server. We tested our tool against malware samples involved in recent cyber attack campaigns, and thus discuss the findings in the paper.
更多
查看译文
AI 解读
一键生成论文网页
Chat Paper
正在生成论文摘要
关键词
Malware,Servers,Computational modeling,Timing,Power grids,Phantoms,Operating systems