Paper published in a book (Scientific congresses, symposiums and conference proceedings)
How Fast Does Malware Leveraging EternalBlue Propagate? The case of WannaCry and NotPetya
Nguyen, Do Duc Anh; Alain, Pierre; Autrel, Fabien et al.
2024In 2024 IEEE 10th International Conference on Network Softwarization, NetSoft 2024
Peer reviewed
 

Files


Full Text
SecSoft.pdf
Author postprint (737.82 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
EternalBlue; Malware infection; NotPetya; Propagation characteristics; WannaCry; Digital infrastructures; Eternalblue; Malware attacks; Malwares; Notpetya; Propagation behavior; Propagation mechanism; Wannacry; Computer Networks and Communications; Software; Safety, Risk, Reliability and Quality
Abstract :
[en] Malware attacks pose a critical threat to digital infrastructures particularly given their potential for widespread and fast propagation. Mitigating them involves limiting their expansion, which requires a thorough understanding of their propagation mechanisms. However, few studies have been conducted on their propagation behaviors in large-scale networks. In this paper, we present the results of an empirical study focusing on the propagation strategy of WannaCry and NotPetya, two malware instances leveraging EternalBlue, an exploit developed by the NSA and stolen by The Shadow Brokers hacker group, which has been used to implement rapid spreading in some mal-ware instances. Our experiments qualify the speed of infection, epidemic behavior, and spreading strategies in a local network of 50 VMs. We have especially measured for WannyCry that (1) nearly 20% of infections are processed in less than 50 seconds, and (2) up to 16 hosts are infected in a 100-second period. Our results provide meaningful insights on malware propagation to support the design of effective countermeasures.
Disciplines :
Computer science
Author, co-author :
Nguyen, Do Duc Anh;  IMT Atlantique, SOTERN - IRISA (UMR CNRS 6074), France
Alain, Pierre;  Université de Rennes, SOTERN - IRISA (UMR CNRS 6074), France
Autrel, Fabien;  IMT Atlantique, SOTERN - IRISA (UMR CNRS 6074), France
Bouabdallah, Ahmed;  IMT Atlantique, SOTERN - IRISA (UMR CNRS 6074), France
FRANCOIS, Jérôme  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SEDAN ; Inria Nancy Grand Est, France
Doyen, Guillaume;  IMT Atlantique, SOTERN - IRISA (UMR CNRS 6074), France
External co-authors :
yes
Language :
English
Title :
How Fast Does Malware Leveraging EternalBlue Propagate? The case of WannaCry and NotPetya
Publication date :
2024
Event name :
2024 IEEE 10th International Conference on Network Softwarization (NetSoft) - SecSoft 2024 - 6th International Workshop on Cyber-Security in Software-defined and Virtualized Infrastructures
Event place :
Saint Louis, Usa
Event date :
24-06-2024 => 28-06-2024
Audience :
International
Main work title :
2024 IEEE 10th International Conference on Network Softwarization, NetSoft 2024
Publisher :
Institute of Electrical and Electronics Engineers Inc.
ISBN/EAN :
9798350369588
Peer reviewed :
Peer reviewed
Funding text :
This work has been partially supported by the French National Research Agency under the France 2030 label (Superviz ANR-22-PECY-0008). The views reflected herein do not necessarily reflect the opinion of the French government.
Available on ORBilu :
since 19 December 2024

Statistics


Number of views
105 (0 by Unilu)
Number of downloads
40 (0 by Unilu)

Scopus citations®
 
3
Scopus citations®
without self-citations
3
OpenCitations
 
0
OpenAlex citations
 
3

Bibliography


Similar publications



Contact ORBilu