• No results found

Goncharov VB2011 pdf

N/A
N/A
Protected

Academic year: 2020

Share "Goncharov VB2011 pdf"

Copied!
53
0
0

Loading.... (view fulltext now)

Full text

(1)

Using Traffic Direction Systems

to simplify fraud... and complicate investigations!

(2)

User

Site

(3)

User

Script-in-the-middle

Site

Site

(4)

User

Site

Database

Control

Panel

Statistics

Filtering

System to separate traffic?

(5)

User

Database

Control

Panel

Statistics

Filtering

Site

Site

Site

Traffic Direction System?

T

raffic

D

irection

(6)

Fingerprint

GET /1/1/typical.php HTTP/1.1

Accept: image/gif, image/x-xbitmap, image/jpeg, application/x-shockwave-flash, */*

Referer:

http://www.trendmicro.com/news

Accept-Language:

en-us

UA-CPU: x86

Accept-Encoding: gzip, deflate

(7)

T

raffic

D

irection

S

ystem

(8)

T

raffic

D

irection

S

ystem

Control traffic directions

Main TDS functionality

By Browser

By OS

By Geo location

By Time

(9)

T

raffic

D

irection

S

ystem

Control traffic directions

Filter non wished traffic

Main TDS functionality

By Browser

By OS

By Geo location

By Time

By Referrer

By Know IP Subnets

By Search Engine Ref.

(10)

T

raffic

D

irection

S

ystem

Control traffic directions

Filter non wished traffic

Collect statistics

Main TDS functionality

By Browser

By OS

By Geo location

By Time

By Referrer

By Know IP Subnets

By Search Engine Ref.

By already seen IPs

For Partnerka

For Referrals

(11)

Farma

Black

SEO

Exploit

Adult

SMS

Areas of usage.

T

raffic

D

irection

(12)

Volume makes money

T

raffic

D

irection

(13)

Web User Fraud : <IFrame/>

(14)

Web User Fraud : <IFrame/>

iframe

EN

DE

FR

(15)

Web User Fraud : <IFrame/>

iframe

T

raffic

D

irection

S

ystem

EN

DE

FR

ES

(16)

Web User Fraud : <IFrame/>

iframe

T

raffic

D

irection

S

ystem

DE

DE

DE

DE

DE

XP

+

XP

(17)

Web User Fraud : <IFrame/>

iframe

T

raffic

D

irection

S

ystem

DE

DE

DE

DE

DE

XP

+

XP

95

V

7

+

MZ

(18)

Malware Vector TDS

iframe

T

raffic

D

irection

S

ystem

MPack

DE

XP

+

+

(19)

Malware Vector multi layer TDS

iframe

T

raffic

D

irection

S

ystem

#1

MPack

Phenix

Eleonore

T

raffic

D

irection

S

ystem

#2

(20)

Partnerka

is an affiliate marketing program, in which the

partners are payed off for online distribution of legal or

illegal content.

(21)

TDS Partnerka - Possible fraud

TDS Partnerka

is an affiliate marketing program, in

which the partners are payed off for exchange of the

Web Traffic and its monetization

(22)
(23)

TDS Software

(24)

Simple TDS

Sutra TDS

Crazy TDS

Kalisto TDS

ILTDS

Advanced TDS

Keitaro TDS

(25)

Simple TDS

Sutra TDS

Crazy TDS

Kalisto TDS

ILTDS

Advanced TDS

Keitaro TDS

(26)

White to Black

Sutra TDS

Sutra TDS

Sutra TDS

Simple TDS

(27)

Traffic Fraud using TDS

intentional

unintentional

traffic sold to the

traffic market

traffic sold to PPI

traffic paid as usage fee

of the TDS software

traffic paid as usage

fee of the TDS service

(28)

Traffic Fraud using TDS

(29)
(30)
(31)

Ransomware example

crawler

US IP Address

+

en-gb header

TDS Direct

traffic by

Geo IP and

(32)

Ransomware example

crawler

RU IP Address

+

ru header

TDS Direct

traffic by

Geo IP and

(33)

Analytic

Synthetic

request

result

(34)

Detecting TDS

(35)

Detecting TDS

IP

Analytic

(36)

Detecting TDS

IP

Language

Analytic

(37)

Detecting TDS

IP

Language

Browser

Analytic

85.114.156.56

EN-US / DE / FR / RU

(38)

Detecting TDS

IP

Language

Browser

OS

Analytic

85.114.156.56

EN-US / DE / FR / RU

(39)

Detecting TDS

IP

Language

Browser

OS

Date/Time

Analytic

85.114.156.56

EN-US / DE / FR / RU

Mozilla / IE / Safari

Win95 / WinXP / MacOS

(40)

Detecting TDS

(41)

Detecting TDS

Web Server Structure

Synthetic

(42)

Detecting TDS

Web Server Structure

Known File Names

Synthetic

http://domain.com/path

(43)

Detecting TDS

Web Server Structure

Known File Names

Known Folder Names

Synthetic

http://domain.com/path

/config/ /logs/ /temp

(44)

Detecting TDS

Web Server Structure

Known File Names

Known Folder Names

Variable Names

Synthetic

http://domain.com/path

/config/ /logs/ /temp

(45)
(46)
(47)
(48)
(49)

Conclusion

Traffic Direction Services

New form of underground business

Really difficult to observe

Mixed with legitimate traffic resale

Challenge AV industry in investigations/sourcing

(50)
(51)

Thanks!

(52)

Thanks!

(53)

Thanks!

t: www.just-a-stie.com http://domain.com/path

References

Related documents

As can be seen in Table 2, the intervention group showed superior functioning at post-treatment on measures of seven cognitive domains: general cognitive functioning

Diijinkan menggunakan sebagian atau seluruh materi pada modul ini, baik berupa ide, foto, tulisan, konfigurasi, diagram, selama untuk. kepentingan pengajaran, dan memberikan kredit

Ifmanagement orthose charged with governance imposea limitation onthe scope of the auditor’s work in theterms of a proposed audit engagement such that the auditor believesthe

Note: Candidates completing their qualifying degree by September 2012, are required to specify the aggregate % marks upto last completed semester, in the box provided

Interest is the small amount of money a bank pays on your savings account. Will you need a picture ID to start

Research and Monetary Policy Department, Central Bank of the Republic of

It has been argued by researchers based on the case of chemical sector that environmental control standards are important for incorporation across the chemical SC

A Resolution accepting the proposal of Marsh USA Inc., in an amount not to exceed $335,000.00 to serve as the System’s Commercial Insurance Broker of Record and to provide