darknet analysis - kiras.at · classification: public 3 underground markeplaces • trading places...

13
Darknet Analysis Peter KIESEBERG

Upload: others

Post on 22-Jun-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Darknet Analysis

PeterKIESEBERG

Page 2: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 1

Darknet Analysis

Privacy-aware automated analysis of underground marketplaces

Page 3: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 2

The deep and the dark

SBA Research gGmbH, 2018

Taken from: https://www.deepweb-sites.com/

Page 4: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 3

Underground markeplaces •  Trading places

o  Malware (e.g. Ransomware, Bot nets)

o  Weapons, Drugs …

•  Based on different technologies o  Often TOR hidden services

o  Payment via Crypto-Currencies

•  Famous example: Silkroad

SBA Research gGmbH, 2018

Page 5: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 4

Goals Ø  Trends in the underground economy

Ø  Automated analysis of underground marketplaces

Ø  Four main targets: o  Automated information retrieval

o  Privacy sensitive analysis

o  Data protection and legal issues

o  Analysis of underground marketplaces

SBA Research gGmbH, 2018

Page 6: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 5

Special requirements 1.  Stealthy reconnaissance 2.  Privacy protection

3.  High degree of automation

4.  Integration with existing tools and workflows

SBA Research gGmbH, 2018

Page 7: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 6

Non-Goals Ø De-anonymization of TOR-traffic

Ø  Linking hidden services to actual places

Ø  Taking down marketplaces

Ø Comprehensive analysis of the market

SBA Research gGmbH, 2018

Page 8: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 7

Solution approach Ø  Iterative approach

Ø Several complete overhauls

Ø  Including structure

Ø Reducing size to app. 50 pages

SBA Research gGmbH, 2018

Page 9: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 8

Special Focus: Automation Core issue: Providers of UMs try to detect reconnaissance

Ø Source detection & generation

Ø Solving Captcha

Ø Automated profile generation

Ø Simulating user behavior

SBA Research gGmbH, 2018

Page 10: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 9

Privacy sensitive analysis Core issue: Provide analytical methods that respect privacy

Ø Study on the effects of anonymization on ML

Ø Privacy by Design in the reconnaissance process

Ø  Trends versus detailed analysis

Ø PAML SBA Research gGmbH, 2018

Page 11: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 10

Data Protection Ø Core issue: Protect the data collection for use as

evidence.

Ø Audit & Control

Ø Manipulation Detection

Ø  Traceability

SBA Research gGmbH, 2018

Page 12: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 11

Partners •  SBA Research •  TU Graz

•  University of Vienna (GSK)

•  Bravestone GmbH

•  BM.I

•  BMLV

SBA Research gGmbH, 2018

Page 13: Darknet Analysis - kiras.at · Classification: Public 3 Underground markeplaces • Trading places o Malware (e.g. Ransomware, Bot nets) o Weapons, Drugs … • Based on different

Classification: Public 12

Peter Kieseberg Research Coordinator SBA Research gGmbH Favoritenstraße 16, 1040 Vienna +43 660 312 6291 [email protected]

SBA Research gGmbH, 2018