À propos de cette session
Masarah Paquet-Clouston et Serge-Olivier Paquette racontent un parcours de recherche parti du botnet bancaire Android Geost pour aboutir à un portrait statistique d'une main-d'œuvre informelle en périphérie de la cybercriminalité. Un journal de clavardage Skype privé d'environ 6 000 messages en russe entre 32 personnes qui diffusaient les APK infectés de Geost a révélé trois acteurs clés, un entrepreneur, un développeur et un webmestre, qui publiaient aussi sur searchengines.guru, un forum russe de marketing Web. À partir des données de Flare Systems, ils ont projeté 400 000 usagers du forum avec UMAP, mené une analyse thématique du clavardage (milieu hostile, amateurisme, tolérance envers l'illégalité) et situé le trio près du centre indifférencié de la carte. Un appariement de pseudonymes avec filtres d'entropie et de temps a identifié environ 1 500 « drifters » actifs sur 38 forums criminels, statistiquement indiscernables des autres; une modélisation de trajectoires montre que les trois quarts restent « curieux du crime » et qu'un quart migre pour de bon. Extrapolé aux forums semblables, cela fait des centaines de milliers de travailleurs opportunistes, que les politiques publiques devraient viser par des débouchés légitimes plutôt qu'en ne traquant que les délinquants motivés.
By focusing on the most visible cybercriminals, our security community often overlooks the impact of massive groups supporting criminal activities. Yet, these groups act like the “mass effect”, where a primary pathology generates
an inflating mass that pressures its surrounding, increasing the initial problem’s scale. This research was motivated by a desire to uncover the context and motivations of individuals involved in spreading the Geost
banking Trojan, and ended with large-scale statistical analyses of behaviors in an informal online market, one of the largest out there. The market was found to host dubious activities through a hide in plain sight approach.
The research unexpectedly opened-up an alternative way of conceptualizing cybercrime economies, one that includes an ordinary working class, involved in any
economic activity for the sake of little crumbs of profit. More than that, we realized that the motives of these individuals did not represent the excitement that is traditionally depicted by cybersecurity storytelling, nor
they embodied the criminal ethos. What is concerning is rather their aggregated effect, their growing mass.
This presentation shares our research journey, depicting the actors involved in the operation of a botnet, their motivations, challenges, and an analysis of the informal market in which they grounded their criminal activities. By using machine learning techniques and a statistical analysis of the informal market population, we found other similar opportunistic entrepreneurs. The analysis also indicated that the informal market may be a revolving door to underground, more criminally prone, communities.
Through this research, we hope to provide researchers, law enforcement officials and policy makers a better grasp on this type of cybercrime economy and a point of view that is closer to what these individuals actually experience.
À retenir
- Regarder au-delà des opérateurs du botnet : la diffusion de maliciels repose sur une main-d'œuvre périphérique peu qualifiée et mal payée, recrutée sur des forums ordinaires.
- Des journaux de clavardage privés trouvés sur VirusTotal peuvent être jumelés aux données de forums publics pour reconstituer qui fait quoi dans une opération criminelle.
- La réutilisation de pseudonymes entre plateformes, filtrée par entropie et fenêtre temporelle, donne une borne inférieure défendable du chevauchement entre communautés légitimes et criminelles.
- Ne pas s'attendre à ce que le comportement de publication trahisse les drifters; sur ce forum, aucune variable testée ne les distinguait des autres usagers.
- Les politiques de prévention devraient offrir des débouchés légitimes aux « curieux du crime » plutôt que de ne viser que les délinquants motivés.
Conférenciers
Masarah is an assistant professor at Université de Montréal and a research collaborator at the Stratosphere Laboratory affiliated with the Czech Technical University in Prague. She holds a Ph.D. in criminology and is specialized in the study of… Lire la suiteRéduire
Masarah is an assistant professor at Université de Montréal and a research collaborator at the Stratosphere Laboratory affiliated with the Czech Technical University in Prague. She holds a Ph.D. in criminology and is specialized in the study of profit-driven crime enabled by technologies. Previously, she worked five years at GoSecure as a researcher and has presented at international conferences including NorthSec, BlackHat, DEFCON and RSA.

Serge-Olivier Paquette is the senior manager of data science at Secureworks. His research focuses on the ability to infer, through machine learning, the context of security events from incomplete information. He also serves as President for… Lire la suiteRéduire
Serge-Olivier Paquette is the senior manager of data science at Secureworks. His research focuses on the ability to infer, through machine learning, the context of security events from incomplete information. He also serves as President for Northsec, a non-profit organization that hosts a series of world-class technical cyber security events, held annually in Montreal.

Sebastian Garcia is a network malware researcher and Assistant Professor that has extensive experience in machine learning applied to network traffic. He created the Stratosphere IPS project, a machine learning-based, free software IPS to protect… Lire la suiteRéduire
Sebastian Garcia is a network malware researcher and Assistant Professor that has extensive experience in machine learning applied to network traffic. He created the Stratosphere IPS project, a machine learning-based, free software IPS to protect the civil society. He likes to analyze network patterns and attacks with machine learning. As a researcher in the AIC group of Czech Technical University in Prague, he believes that free software and machine learning tools can help better protect users from abuse of their digital rights. He has been teaching in several countries and Universities and working on penetration testing for both corporations and governments. He was lucky enough to speak at Ekoparty, DeepSec, Hacktivity, Botconf, Hacklu, InBot, SecuritySessions, ECAI, CitizenLab, ArgenCon, Free Software Foundation Europe, VirusBulletin, BSides Vienna, HITB Singapore, CACIC, etc. As a co-founder of the MatesLab hackspace he is a free software advocate that worked on honeypots, malware detection, distributed scanning (dnmap) keystroke dynamics, Bluetooth analysis, privacy protection, intruder detection, robotics, microphone detection with SDR (Salamandra) and biohacking.

