• DocumentCode
    3007657
  • Title

    Software updates as a security metric: Passive identification of update trends and effect on machine infection

  • Author

    Khan, Mahrukh ; Zehui Bi ; Copeland, J.A.

  • Author_Institution
    Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2012
  • fDate
    Oct. 29 2012-Nov. 1 2012
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Botnets have become a vital part of underground economy and botherders are actively looking for new recruits to join their bot army. A lapse by an end user or an administrator in terms of not updating their software enables the botherder to achieve this objective. In this paper we will investigate the phenomenon of a machine infection from the perspective of a user update behavior. We also present type of attacks that are launched by hackers to compromise machine and the vulnerabilities that lead to such attacks as a result of update behavior. We will also characterize the user update behavior on the test network of study. Finally we will compare the update behavior of machines that were infected with the ones that were not infected. The objective of this investigation is to see if update behavior could be used as an effective security metric, our trends show that there is a very clear correlation between the machines that were infected and the machines that were not updated.
  • Keywords
    computer crime; configuration management; invasive software; software metrics; bot army; botherder; botnet; hacker attack; machine infection; malware; passive identification; security metric; software update; underground economy; user update behavior; Internet; Malware; Market research; Measurement; Servers; Software; bothunter; botnet; malware; software updates;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    MILITARY COMMUNICATIONS CONFERENCE, 2012 - MILCOM 2012
  • Conference_Location
    Orlando, FL
  • ISSN
    2155-7578
  • Print_ISBN
    978-1-4673-1729-0
  • Type

    conf

  • DOI
    10.1109/MILCOM.2012.6415869
  • Filename
    6415869