arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.30070cs.CR

信息窃取恶意软件受害者的数据驱动分析

A Data-Driven Analysis of Infostealer Malware Victims

Arttu Paju, Juha Nurmi, David Arroyo, Sergio Chica Manjarrez, Fran Casino, Mikko Niemelä, Juuso Itkonen, Joel Scanlan, Constantinos Patsakis, Georgios Smaragdakis

首次发表
浏览论文内容

中文总结 AI 辅助

本研究构建隐私保护流水线,将非法信息窃取日志转化为含170,298名受害者的数据集,发现高价值组织凭证受损及凭证重用问题,并发布首个匿名化数据集以支持可复现研究。

中文摘要 AI 辅助

信息窃取恶意软件感染全球设备,并窃取其最敏感的内容:凭证、浏览器会话、私钥和访问证书。然而,在没有道德、合法且经过整理的研究数据集的情况下,其受害者的影响难以研究。为弥补这一空白,我们构建了一个隐私保护流水线,将非法来源的信息窃取日志转化为可复现的研究工件,在保留测量效用的同时最小化敏感数据,并利用该流水线从多个信息窃取恶意软件家族的日志中构建了一个包含170,298名受害者的数据集。分析这些受害者,我们发现受影响最严重的服务与全球最流行的平台相呼应,其中游戏和娱乐服务占比显著过高。在样本中,我们识别出针对高价值组织的受损凭证,包括执法领域域名、政府和军事服务以及全部八所常春藤盟校,同时还有大量安全关键基础设施以及金融、远程访问和开发平台的暴露。受害者还表现出广泛的凭证重用和显著的再次受害风险,与网络钓鱼和勒索软件受害者群体存在重叠。我们在受控访问下发布了首个匿名化的受害者级信息窃取数据集,以支持关于信息安全和受害者行为的道德、隐私保护和可复现研究。

英文摘要

Infostealer malware infects devices worldwide and harvests their most sensitive contents: credentials, browser sessions, private keys, and access certificates. Yet its impact on victims remains difficult to study without an ethical, legal, and curated research dataset. To close this gap, we build a privacy-preserving pipeline that turns illicitly sourced infostealer logs into a reproducible research artifact, minimizing sensitive data while preserving measurement utility, and use it to construct a dataset of 170,298 victims from logs of multiple infostealer families. Analyzing these victims, we find that the most compromised services mirror the world's most popular platforms, with gaming and entertainment services strongly overrepresented. Within the sample we identify compromised credentials for high-value organizations, including law-enforcement domains, government and military services, and all eight Ivy League universities, as well as substantial exposure of security-critical infrastructure and of financial, remote-access, and development platforms. Victims also show widespread credential reuse and significant revictimization risk, overlapping with phishing and ransomware victim populations. We release the first anonymized victim-level infostealer dataset under controlled access to enable ethical, privacy-preserving, and reproducible research on information security and victim behavior.

发表机构

  • Tampere University(坦佩雷大学)
  • Consejo Superior de Investigaciones Científicas (CSIC)(西班牙国家研究委员会)
  • Universitat Rovira i Virgili(罗维拉-依维尔吉利大学)
  • Athena Research Center(雅典研究中心)
  • Cyber Intelligence House(网络情报之家)
  • Macquarie University(麦考瑞大学)
  • University of Tasmania(塔斯马尼亚大学)
  • University of Piraeus(比雷埃夫斯大学)
  • Delft University of Technology(代尔夫特理工大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑