ripple effect (preso @s4)

21
Ripple Effect Algorithmic Threat Intelligence & Containment Ping @OpenDNS.com

Upload: ping-yan

Post on 14-Jan-2015

213 views

Category:

Technology


2 download

DESCRIPTION

containing cryptolocker. Security analytics with DNS transactions.

TRANSCRIPT

Page 1: Ripple Effect (preso @s4)

Ripple EffectAlgorithmic Threat

Intelligence & ContainmentPing @OpenDNS.com

Page 2: Ripple Effect (preso @s4)

Ping

Came from China Was in U. of Arizona graduate school

Data mining, Machine learningInfoSec

Page 3: Ripple Effect (preso @s4)

Agenda

DNS transactions

The Ripple Effect

Case study - Cryptolocker

Demo

Page 4: Ripple Effect (preso @s4)

More IP, AS intel, the present and the past?

What is this traffic spikes all about?

Page 5: Ripple Effect (preso @s4)

What are all these weird stuff that one was requesting?

Page 6: Ripple Effect (preso @s4)
Page 7: Ripple Effect (preso @s4)

The Ripple Effect

The process of searching the newer and the unknown, … starting from the seeding intelligence

Page 8: Ripple Effect (preso @s4)
Page 9: Ripple Effect (preso @s4)
Page 10: Ripple Effect (preso @s4)

Cryptolocker DGA

1. Infection2. retrieve encryption key from CnC3. encrypt data files 4. collect money!

IP CnC fails quickly! DGA kicks in !

Page 11: Ripple Effect (preso @s4)
Page 12: Ripple Effect (preso @s4)
Page 13: Ripple Effect (preso @s4)

I don’t know the DGA!!!

Page 15: Ripple Effect (preso @s4)
Page 17: Ripple Effect (preso @s4)

The Algorithm

Page 18: Ripple Effect (preso @s4)

November 7th 144.76.192.13095.59.26.43

Page 20: Ripple Effect (preso @s4)
Page 21: Ripple Effect (preso @s4)

QUESTIONS?