OnionBots: Subverting Privacy Infrastructure for Cyber Attacks
Amirali Sanatinia, Guevara Noubir

TL;DR
This paper introduces OnionBots, a new resilient and stealthy type of botnet that exploits privacy infrastructures like Tor to evade detection, and proposes mitigation strategies to counteract them.
Contribution
The paper presents the design of OnionBots, analyzes their resilience, and develops the SOAP mitigation technique, highlighting the need for proactive detection methods.
Findings
OnionBots can operate anonymously within privacy infrastructures.
They are robust to network partitioning and node deletions.
SOAP effectively neutralizes OnionBot nodes.
Abstract
Over the last decade botnets survived by adopting a sequence of increasingly sophisticated strategies to evade detection and take overs, and to monetize their infrastructure. At the same time, the success of privacy infrastructures such as Tor opened the door to illegal activities, including botnets, ransomware, and a marketplace for drugs and contraband. We contend that the next waves of botnets will extensively subvert privacy infrastructure and cryptographic mechanisms. In this work we propose to preemptively investigate the design and mitigation of such botnets. We first, introduce OnionBots, what we believe will be the next generation of resilient, stealthy botnets. OnionBots use privacy infrastructures for cyber attacks by completely decoupling their operation from the infected host IP address and by carrying traffic that does not leak information about its source, destination,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · Internet Traffic Analysis and Secure E-voting
