ImageVerifierCode 换一换
格式:PPT , 页数:31 ,大小:454.50KB ,
文档编号:5183077      下载积分:25 文币
快捷下载
登录下载
邮箱/手机:
温馨提示:
系统将以此处填写的邮箱或者手机号生成账号和密码,方便再次下载。 如填写123,账号和密码都是123。
支付方式: 支付宝    微信支付   
验证码:   换一换

优惠套餐
 

温馨提示:若手机下载失败,请复制以下地址【https://www.163wenku.com/d-5183077.html】到电脑浏览器->登陆(账号密码均为手机号或邮箱;不要扫码登陆)->重新下载(不再收费)。

已注册用户请登录:
账号:
密码:
验证码:   换一换
  忘记密码?
三方登录: 微信登录  
下载须知

1: 试题类文档的标题没说有答案,则无答案;主观题也可能无答案。PPT的音视频可能无法播放。 请谨慎下单,一旦售出,概不退换。
2: 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。
3: 本文为用户(晟晟文业)主动上传,所有收益归该用户。163文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知163文库(点击联系客服),我们立即给予删除!。
4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
5. 本站仅提供交流平台,并不能对任何下载内容负责。
6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

版权提示 | 免责声明

1,本文(Can-You-Infect-Me-Now-Malware-Propagation-in-Mobile-Phone-你能感染我现在的手机恶意软件的传播课件.ppt)为本站会员(晟晟文业)主动上传,163文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。
2,用户下载本文档,所消耗的文币(积分)将全额增加到上传者的账号。
3, 若此文所含内容侵犯了您的版权或隐私,请立即通知163文库(发送邮件至3464097650@qq.com或直接QQ联系客服),我们立即给予删除!

Can-You-Infect-Me-Now-Malware-Propagation-in-Mobile-Phone-你能感染我现在的手机恶意软件的传播课件.ppt

1、Mobile MalwareLike normal malware,but on mobile phones(smart phones and dumb ones too)Why worry about mobile malware?“combination of vulnerable platforms(symbian),unsuspecting users,and explosive growth in potential victims will inevitably attract propagating malware”What Makes This Paper Different?

2、Previous malware propagation research:Proximity PropagationBluetooth,etcThis research:Focuses on propagation via the telecommunications networkWhy Moble Malware?(from the bad guys perspective)Smart phones are a lot like PCs:market share per OS(72%symbian)software vulnerabilities existExploited smart

3、 phones could provide an attacker with means to:steal private data/users identitiesspammake free callsexecute(D)DoSMain Paper Goal(s)Simulate the effects of mobile malware propagation via the telecommunications networkSimulated both VoIP malware and MMS malwareDraw some conclusions for defendingSimu

4、latorEvent Driven,Custom Code.(so they could better adapt for their needs)1 second step size,stepping 12 hoursInfection beginning at a single phoneTelecom NetworkUMTSTopologyBoston Metro AreaNetwork:UMTSUMTS is the 3G successor to GSM(2.5G/GPRS,2.75G/EDGE)Network side is very similar to GSM,air inte

5、rface side changed to support higher data rates.Signaling and control are negligible(ignored in the model)Topology:Boston Metro Area100sq miles,divided into 1sq mile cellsMobile Station Distributionfrom US Census datascaled by 78%(by cell phone penetration)Mobility is not modeledAuthors speculate th

6、e bottleneck will be in the network,not at the air interfaceSimplified UTMS NetworkSimulation ConstructionAssume normal MMS usage is based on a charge per messageMMS Server CapacityServer handles 100 msg/sec,although higher rates were simulated with“a qualitatively similar result”Authors explanation

7、:MMS server will not be dimensioned to handle users behaving like an aggressive worm(i.e.,sending large numbers of messages as quickly as possible).Bottom-up design of the UMTS NetworkSimplified UTMS NetworkSimplified UTMS NetworkSimplified UTMS NetworkSimplified UTMS NetworkSimplified UTMS NetworkS

8、implified UTMS NetworkSimplified UTMS NetworkModeled UTMS NetworkSimulation Parameters1 single serverserving 100 msg/sec49 serversserving 10k users each49 servers9616 Node Bs2Mbps100Mbps1Gbps links between SGSNsSimulation Notes“The granularity of our Node B placement was a limiting factor of our ini

9、tial population data.A finer granularity would,no doubt,offer a more detailed and accurate picture of malware propagation.”Spreading via Phone books/Contact ListsNo published studies of address book characteristics found,so:1-1000 contacts(upper limit from empirical data on phone book maximums)Phone

10、 book/contact degree distributions based on statistical analysisPhonebook/contact degree distributions(for contact list size)Power-Law:from yahoo email groups,and other authors research.Log-Normal:from social networking websites statistics.Erlang Dist:from authors experiment(but very small sample si

11、ze of 73)Node Attachment.you dont call everybody in your address bookProbabilistically randomly assign address book size based on distribution,then.70%-“The probability that two users were friends was proportional to the inverse of the number of people between them.”(from LiveJournal study)30%unifor

12、mly randomly assignedAttack Vector:VoIPAssumes vulnerable service on the mobile phone which does not require user interactionAssume all phones are vulnerable.(Authors note that in reality a fraction would be vulnerable,and they state a qualitatively similar result)Simulated Propagation of VoIP Malwa

13、re“.constrained bandwidth should also be considered;but doing so requires estimating typical traffic characteristics,and we lacked meaningful data on which to base such estimates.”-?Techniques for Faster Propagation of VoIP Malware(and Simulation Results)Divide and distribute(transfer)contacts from

14、address bookCongestion backoff(wait)10sAttack Vector:MMSHandled by central MMS serverRequires user interactiononly a percentage“F”act on messageCan be done while phone is offSo there is a wait time to answer messages.Mixture of two Gaussian distributions centered at 20s&45mSimulated Propagation of M

15、MS MalwareTechniques for Faster Propagation of MMS MalwareCongestion backoff(10s)Not very much advantage,due to MMS central server constraint.Divide and distribute contacts from address bookSame as aboveGlobal contact book methodInfected half the population in 12 hrs.(what F value?)Faster MMS Malwar

16、e PropagationDefending Against Mobile Malware Propagation in Telecom.Networks(This section is way too small in the paper,would have liked to see more on this.)Rate LimitingACCELLERATES infection!(same as congestion avoidance)Blacklisting Containmentlarge number still get infected more slowly(no deta

17、ils given on%).removing phones leads to a less congested network for those infected but non-blacklisted phonesContent Filtering“Seems promising due to centralized topology.”Investigating whether its practical remains future work.(and they didnt provide any information on how promising or why)Questions?

侵权处理QQ:3464097650--上传资料QQ:3464097650

【声明】本站为“文档C2C交易模式”,即用户上传的文档直接卖给(下载)用户,本站只是网络空间服务平台,本站所有原创文档下载所得归上传人所有,如您发现上传作品侵犯了您的版权,请立刻联系我们并提供证据,我们将在3个工作日内予以改正。


163文库-Www.163Wenku.Com |网站地图|