Addressing Device Compromise from the Perspective of Large Organizations

Louis F. DeKoven · eScholarship (California Digital Library) · 2019

Addressing compromised device is a problem for virtually all largeorganizations. Compromised devices can propagate malware resulting intheft of computing resources, loss of sensitive data, and extortion ofmoney. Unfortunately, large organizations do not have an oracle intodevice compromise. Instead, organizations must address compromisewithout straightforward answers to critical questions such as: "Isthis device compromised?", "Why/How is this device compromised?","What's the correct intervention?". This problem, in part, resultsfrom limited observational vantage points, differences in interventioncapabilities, and evolving adversaries with differing incentives. Inthis dissertation, I develop systems that empirically address multipletypes of device compromise using large-scale observations withindifferent organizations, thus placing us on a stronger footing todevise better interventions.I first describe an approach used at Facebook for detecting maliciousbrowsers extensions. I present a methodology whereby users exhibitingsuspicious online behaviors are scanned (with permission) to identifyextensions in their browsers, and those extensions are in turn labeledbased on the threat indicators they contain. Employing thismethodology at Facebook I identify more than 1,700 lexically distinctmalicious extensions, and use this labeling to drive user deviceclean-up efforts as well notify browser vendors.Next, I examine for-profit services offering to artificiallymanipulate a user's social standing on Instagram. I identify thetechniques used by these services to drive social actions, detail howthey are structured to evade straightforward detection, andcharacterize the dynamics of their customer base. Finally, I constructcontrolled experiments to disrupt these services and analyze howdifferent approaches to intervention can drive different reactions,thus providing distinct trade-offs for defenders.Lastly, I describe a large-scale measurement of 15,000 laptop anddesktop devices on a university's network to characterize theprevalence of security "best practices" and security-relevantbehaviors, and quantify how they relate to device compromise. I usepassive network traffic analysis techniques to infer a broad range ofdevice features and per-machine compromise state. I find a number ofbehaviors positively correlate with host compromise, and few "bestpractices" exhibit negative correlations that would support theirvalue in improving end user security.

Read the paper · More papers on PaperTik