Leveraging Bitcoin Testnet for Bidirectional Botnet Command and Control Systems

06/10/2020
by   Federico Franzoni, et al.
0

Over the past twenty years, the number of devices connected to the Internet grew exponentially. Botnets benefited from this rise to increase their size and the magnitude of their attacks. However, they still have a weak point in their Command Control (C C) system, which is often based on centralized services or require a complex infrastructure to keep operating without being taken down by authorities. The recent spread of blockchain technologies may give botnets a powerful tool to make them very hard to disrupt. Recent research showed how it is possible to embed C C messages in Bitcoin transactions, making them nearly impossible to block. Nevertheless, transactions have a cost and allow very limited amounts of data to be transmitted. Because of that, only messages from the botmaster to the bots are sent via Bitcoin, while bots are assumed to communicate through external channels. Furthermore, for the same reason, Bitcoin-based messages are sent in clear. In this paper we show how, using Bitcoin Testnet, it is possible to overcome these limitations and implement a cost-free, bidirectional, and encrypted C C channel between the botmaster and the bots. We propose a communication protocol and analyze its viability in real life. Our results show that this approach would enable a botmaster to build a robust and hard-to-disrupt C C system at virtually no cost, thus representing a realistic threat for which countermeasures should be devised.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/29/2018

Tithonus: A Bitcoin Based Censorship Resilient System

Providing reliable and surreptitious communications is difficult in the ...
research
07/16/2021

Blockchain Technology: Bitcoins, Cryptocurrency and Applications

Blockchain is a decentralized ledger used to securely exchange digital c...
research
04/04/2020

Attacking with bitcoin: Using Bitcoin to Build Resilient Botnet Armies

We focus on the problem of botnet orchestration and discuss how attacker...
research
09/21/2021

3-of-3 Multisignature Approach for Enabling Lightning Network Micro-payments on IoT Devices

Bitcoin's success as a cryptocurrency enabled it to penetrate into many ...
research
07/09/2019

Characterizing Bitcoin donations to open source software on GitHub

Web-based hosting services for version control, such as GitHub, have mad...
research
12/07/2019

A percolation model for the emergence of the Bitcoin Lightning Network

The Lightning Network is a so-called second-layer technology built on to...
research
12/23/2019

LNBot: A Covert Hybrid Botnet on Bitcoin Lightning Network

While various covert Botnets were proposed in the past, they still lack ...

Please sign up or login with your details

Forgot password? Click here to reset