Using Honeybuckets to Characterize Cloud Storage Scanning in the Wild

التفاصيل البيبلوغرافية
العنوان: Using Honeybuckets to Characterize Cloud Storage Scanning in the Wild
المؤلفون: Izhikevich, Katherine, Voelker, Geoff, Savage, Stefan, Izhikevich, Liz
سنة النشر: 2023
المجموعة: Computer Science
مصطلحات موضوعية: Computer Science - Cryptography and Security, Computer Science - Networking and Internet Architecture
الوصف: In this work, we analyze to what extent actors target poorly-secured cloud storage buckets for attack. We deployed hundreds of AWS S3 honeybuckets with different names and content to lure and measure different scanning strategies. Actors exhibited clear preferences for scanning buckets that appeared to belong to organizations, especially commercial entities in the technology sector with a vulnerability disclosure program. Actors continuously engaged with the content of buckets by downloading, uploading, and deleting files. Most alarmingly, we recorded multiple instances in which malicious actors downloaded, read, and understood a document from our honeybucket, leading them to attempt to gain unauthorized server access.
نوع الوثيقة: Working Paper
URL الوصول: http://arxiv.org/abs/2312.00580
رقم الأكسشن: edsarx.2312.00580
قاعدة البيانات: arXiv