Cargando…

DUSTBot: A duplex and stealthy P2P-based botnet in the Bitcoin network

As the root cause of illegal cyber activities, botnets are evolving continuously over the last two decades. Current researches on botnet command and control mechanism based on blockchain network suffer from high economic cost, single point of failure, and limited scalability. In this paper, we prese...

Descripción completa

Detalles Bibliográficos
Autores principales: Zhong, Yi, Zhou, Anmin, Zhang, Lei, Jing, Fan, Zuo, Zheng
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Public Library of Science 2019
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6924649/
https://www.ncbi.nlm.nih.gov/pubmed/31860660
http://dx.doi.org/10.1371/journal.pone.0226594
_version_ 1783481756439019520
author Zhong, Yi
Zhou, Anmin
Zhang, Lei
Jing, Fan
Zuo, Zheng
author_facet Zhong, Yi
Zhou, Anmin
Zhang, Lei
Jing, Fan
Zuo, Zheng
author_sort Zhong, Yi
collection PubMed
description As the root cause of illegal cyber activities, botnets are evolving continuously over the last two decades. Current researches on botnet command and control mechanism based on blockchain network suffer from high economic cost, single point of failure, and limited scalability. In this paper, we present DUSTBot, a novel P2P botnet model based on Bitcoin transactions to prepare for new cyber threats. Specifically, a covert, duplex, and low-cost command and control (C&C) channel in the Bitcoin network is presented in our work. DUSTBot uses the Bitcoin main network as the downstream channel while using the Bitcoin testnet as the upstream channel. Furthermore, the peer list exchange algorithm based on the Ethereum block hash proposed in this paper is effective against routing table poisoning attack and P2P botnet crawling. The robustness of DUSTBot against node removal is studied through constructing the botnet with a P2P simulator. We deploy the implementation of DUSTBot on cloud platforms to test its feasibility and performance. Moreover, the stealthiness of DUSTBot and the effectiveness of the proposed peer list exchange algorithm are evaluated. The results demonstrate the feasibility, performance, stealthiness, and robustness of DUSTBot. In the end, possible countermeasures are discussed to mitigate similar threats in the future.
format Online
Article
Text
id pubmed-6924649
institution National Center for Biotechnology Information
language English
publishDate 2019
publisher Public Library of Science
record_format MEDLINE/PubMed
spelling pubmed-69246492020-01-07 DUSTBot: A duplex and stealthy P2P-based botnet in the Bitcoin network Zhong, Yi Zhou, Anmin Zhang, Lei Jing, Fan Zuo, Zheng PLoS One Research Article As the root cause of illegal cyber activities, botnets are evolving continuously over the last two decades. Current researches on botnet command and control mechanism based on blockchain network suffer from high economic cost, single point of failure, and limited scalability. In this paper, we present DUSTBot, a novel P2P botnet model based on Bitcoin transactions to prepare for new cyber threats. Specifically, a covert, duplex, and low-cost command and control (C&C) channel in the Bitcoin network is presented in our work. DUSTBot uses the Bitcoin main network as the downstream channel while using the Bitcoin testnet as the upstream channel. Furthermore, the peer list exchange algorithm based on the Ethereum block hash proposed in this paper is effective against routing table poisoning attack and P2P botnet crawling. The robustness of DUSTBot against node removal is studied through constructing the botnet with a P2P simulator. We deploy the implementation of DUSTBot on cloud platforms to test its feasibility and performance. Moreover, the stealthiness of DUSTBot and the effectiveness of the proposed peer list exchange algorithm are evaluated. The results demonstrate the feasibility, performance, stealthiness, and robustness of DUSTBot. In the end, possible countermeasures are discussed to mitigate similar threats in the future. Public Library of Science 2019-12-20 /pmc/articles/PMC6924649/ /pubmed/31860660 http://dx.doi.org/10.1371/journal.pone.0226594 Text en © 2019 Zhong et al http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
spellingShingle Research Article
Zhong, Yi
Zhou, Anmin
Zhang, Lei
Jing, Fan
Zuo, Zheng
DUSTBot: A duplex and stealthy P2P-based botnet in the Bitcoin network
title DUSTBot: A duplex and stealthy P2P-based botnet in the Bitcoin network
title_full DUSTBot: A duplex and stealthy P2P-based botnet in the Bitcoin network
title_fullStr DUSTBot: A duplex and stealthy P2P-based botnet in the Bitcoin network
title_full_unstemmed DUSTBot: A duplex and stealthy P2P-based botnet in the Bitcoin network
title_short DUSTBot: A duplex and stealthy P2P-based botnet in the Bitcoin network
title_sort dustbot: a duplex and stealthy p2p-based botnet in the bitcoin network
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6924649/
https://www.ncbi.nlm.nih.gov/pubmed/31860660
http://dx.doi.org/10.1371/journal.pone.0226594
work_keys_str_mv AT zhongyi dustbotaduplexandstealthyp2pbasedbotnetinthebitcoinnetwork
AT zhouanmin dustbotaduplexandstealthyp2pbasedbotnetinthebitcoinnetwork
AT zhanglei dustbotaduplexandstealthyp2pbasedbotnetinthebitcoinnetwork
AT jingfan dustbotaduplexandstealthyp2pbasedbotnetinthebitcoinnetwork
AT zuozheng dustbotaduplexandstealthyp2pbasedbotnetinthebitcoinnetwork