SZÁDECZKY, Tamás a Zsolt BEDERNA. Effects of botnets – a human-organisational approach. Security and Defence Quarterly. 2021, roč. 35, č. 3, s. 25-44. ISSN 2300-8741. Dostupné z: https://dx.doi.org/10.35467/sdq/138588.
Další formáty:   BibTeX LaTeX RIS
Základní údaje
Originální název Effects of botnets – a human-organisational approach
Autoři SZÁDECZKY, Tamás (348 Maďarsko, domácí) a Zsolt BEDERNA.
Vydání Security and Defence Quarterly, 2021, 2300-8741.
Další údaje
Originální jazyk angličtina
Typ výsledku Článek v odborném periodiku
Obor 50501 Law
Stát vydavatele Polsko
Utajení není předmětem státního či obchodního tajemství
WWW URL
Kód RIV RIV/00216224:14220/21:00124491
Organizační jednotka Právnická fakulta
Doi http://dx.doi.org/10.35467/sdq/138588
Klíčová slova anglicky botnet; cybersecurity
Změnil Změnil: JUDr. Jakub Klodwig, učo 434044. Změněno: 5. 4. 2022 23:02.
Anotace
Botnets, the remotely controlled networks of computers with malicious aims, have significantly affected the international order from Ukraine to the United States in recent years. Disruptive software, such as malware, ransomware, and disruptive services, provided by those botnets has many specific effects and properties. Therefore, it is paramount to improve the defences against them. To tackle botnets more or less successfully, one should analyse their code, communication, kill chain, and similar technical properties. However, according to the Business Model for Information Security, besides technological attributes, there is also a human and organisational aspect to their capabilities and behaviour. This paper aims to identify the aspects of different attacks and present an analysis framework to identify botnets’ technological and human attributes. After researching the literature and evaluating our previous findings in this research project, we formed a unified framework for the human-organisational classification of botnets. We tested the defined framework on five botnet attacks, presenting them as case studies. The chosen botnets were ElectrumDoSMiner, Emotet, Gamover Zeus, Mirai, and VPNFilter. The focus of the comparison was motivation, the applied business model, willingness to cooperate, capabilities, and the attack source. For defending entities, reaching the target state of defending capabilities is impossible with a one-time development due to cyberspace’s dynamic behaviour and botnets. Therefore, one has to develop cyberdefence and conduct threat intelligence on botnets using such methodology as that presented in this paper. This framework comprises people and technological attributes according to the BMIS model, providing the defender with a standard way of classification.
Návaznosti
EF16_019/0000822, projekt VaVNázev: Centrum excelence pro kyberkriminalitu, kyberbezpečnost a ochranu kritických informačních infrastruktur
VytisknoutZobrazeno: 7. 9. 2024 00:14