[00:00.250 --> 00:08.130] It was kind of hard to choose the title for this presentation, like to convey what it is really about. [00:08.690 --> 00:14.650] So, the whole purpose of my research in general would be to study attackers' behavior. [00:15.350 --> 00:21.910] And we wanted to put that in relation to proxy use, or proxy including VPN and everything. [00:22.250 --> 00:35.970] So, we will be analyzing attackers with the very few information we have and see to what extent we can reach with those few information. [00:36.530 --> 00:49.670] So, we will be navigating geopolitical nuances in cyber attack, but it represents a small portion of the presentation, because it will be inside the results of our analysis. [00:50.010 --> 01:08.390] But the most... the bigger part of the presentation will be on this advanced IP address analysis, which is the name that we give to our whole research process, our geeking out activities about IP addresses. [01:08.390 --> 01:20.510] So, it will not concern traffic analysis, which is really tied to proxy use, but rather identification of proxy use through IP addresses. [01:20.510 --> 01:24.450] So, it will be proxies everywhere and statistics everywhere. [01:24.450 --> 01:26.390] This is what it is about. [01:26.650 --> 01:35.010] So, what makes our talk really cool is because it is at the intersection between social science and engineering. [01:35.770 --> 01:38.990] So, I have a PhD in criminology. [01:39.130 --> 01:47.870] So, I'm interested in attackers' behavior, offenders' behaviors, decision-making, their strategies, all that. [01:47.870 --> 01:59.790] But I also... I work as the director of research at GoSecure, which is a cybersecurity company, but our presentation has nothing to do with the product and services that we sell at that company. [02:00.110 --> 02:07.210] My role is really to deepen the academic or scientific knowledge of the phenomenon in cybersecurity. [02:07.250 --> 02:12.730] So, it's really tied to the human behind the phenomenon. [02:13.830 --> 02:20.030] And I keep close ties with the university as an affiliated professor at Montreal University in Canada. [02:20.850 --> 02:30.750] I'm also involved in my community as a co-VP engagement and outreach for NORDSEC, which is a really cool cybersecurity conference, hacker conference in Montreal in May. [02:30.930 --> 02:33.570] So, if you're interested, please come and see me. [02:33.690 --> 02:36.410] I will be very glad to talk about this event. [02:37.050 --> 02:40.230] And I'm also a board member for the Canadian Cybersecurity Network. [02:40.230 --> 02:43.290] And today, to co-present with me, I have Constance. [02:44.990 --> 02:45.550] All right. [02:45.650 --> 02:46.110] Hi, everyone. [02:46.530 --> 02:47.770] So, I'm Constance. [02:47.910 --> 02:52.630] I'm currently a software engineering student in Concordia University, so back in Montreal, Canada. [02:53.070 --> 02:57.910] And I'm currently interning as a software... a research intern for GoSecure with Andreanne. [02:58.210 --> 03:00.690] I also work part-time as a SOC analyst at one point. [03:00.850 --> 03:06.150] And finally, I'm the president of the Software Engineering Computer Science Society back in Concordia as well. [03:08.490 --> 03:13.750] So, I'll start with the criminology part of the presentation. [03:14.130 --> 03:22.750] So, researcher in criminology has observed that there is a relationship between the type of crime that is committed and the geographic location of the offender. [03:23.010 --> 03:33.850] So, if we concentrate on cybercrime, well, those cybercrime will happen in specific regions with high concentration of technical talent, but low economic opportunities. [03:34.930 --> 03:42.970] So, local geopolitical influences will shape the decision to commit a crime for certain... for the offender. [03:44.070 --> 03:52.290] So, there is cybercrime hubs, but there's also specialization of a certain type of crime for different regions of the world. [03:52.290 --> 03:55.450] And this attribution is not random. [03:55.650 --> 04:03.410] So, there's... the type of cybercrime is tied to the history, the custom manners, the infrastructure of a country. [04:03.670 --> 04:10.210] For example, a romantic scam is tied in research to offender from West Africa. [04:11.110 --> 04:16.950] Hacking would be tied related to... or associated with Russia. [04:17.670 --> 04:23.590] And the Indian seems to have... seems to be specializing in technical support scam. [04:24.130 --> 04:27.870] And if we take this last example for... yeah, more in-depth. [04:28.190 --> 04:35.890] So, they seem to have an infrastructure that is already there that will allow this type of crime. [04:35.890 --> 04:42.330] So, it has been documented already that the call centers that is... there's a lot of call centers there. [04:42.530 --> 04:46.030] And so, they do legitimate activities during the day. [04:46.310 --> 04:50.010] And then the infrastructure is used to transform into illegal activity at night. [04:50.190 --> 04:56.350] So, you understand that there's an infrastructure that allows this... those crimes to happen. [04:57.510 --> 05:02.810] So, studying cybercrime according to the geolocalization of the offender is worth it. [05:02.810 --> 05:03.630] It's very interesting. [05:04.430 --> 05:06.630] But it is not that easy. [05:07.190 --> 05:13.290] So, the use of a computer in the crime makes that there's something in between you and the other person. [05:13.470 --> 05:19.310] So, just there, there's something a bit more difficult than someone who is just stealing there... [05:19.310 --> 05:20.090] ready to get arrested. [05:20.570 --> 05:22.990] So, it's a bit more difficult. [05:23.230 --> 05:28.690] But also, they can be using some kind of technologies to hide their identity further. [05:28.690 --> 05:32.870] So, you all know about the anonymity tools that are out there. [05:33.910 --> 05:38.710] And so, you would be surprised if the amount of research in criminology that has been done... [05:38.710 --> 05:41.930] not only in criminology, but more at large... [05:41.930 --> 05:50.870] that has been done on geographic information of cybercrime, but do not take into consideration that, like, their IP addresses or their relocation can be... [05:51.990 --> 05:54.290] hidden or, you know, changed a little bit. [05:54.290 --> 05:59.230] So, this is where our research come to fill the gap in the literature. [06:00.330 --> 06:08.070] So, just to be clear and make sure that we are all on the same page here, this is our definition of proxy for today's presentation. [06:08.330 --> 06:08.510] Okay? [06:08.930 --> 06:13.810] So, we will define proxy as anything that would help you hide your IP address. [06:14.050 --> 06:16.670] That's the basic definition for today. [06:16.670 --> 06:26.490] So, it includes servers, proxy servers, anonymity network, virtual private network, data center, everything that would just change the IP. [06:27.230 --> 06:27.790] Okay? [06:29.310 --> 06:29.870] Okay. [06:29.870 --> 06:34.190] So, this was the agenda that we had in mind at first to present you. [06:34.310 --> 06:36.790] So, the context of the study, which I just did. [06:37.130 --> 06:38.870] And then, data collection. [06:39.150 --> 06:42.090] How did we collect all the data, the tooling, everything. [06:42.090 --> 06:46.870] And then, our methodology to study proxies. [06:47.310 --> 06:52.010] And then, which will allow us to make the analysis on attackers' behavior. [06:52.310 --> 06:54.890] And then, you know, limits of the study, concluding thought. [06:55.250 --> 07:00.450] But, we kind of fell into a rabbit hole or many rabbit holes. [07:00.650 --> 07:04.650] So, this would be our agenda for today. [07:04.650 --> 07:20.770] So, because when we were at the step of choosing the methodology and choosing a source of information that we can rely on concerning the proxy detection, we figured that it's not that easy to just choose one. [07:20.890 --> 07:22.090] Like, why this one? [07:22.190 --> 07:23.150] Why not another one? [07:23.190 --> 07:26.910] So, we started comparing the different source of information. [07:28.090 --> 07:31.510] And after that, like, which one is right? [07:31.510 --> 07:33.310] So, we had to test for the truth. [07:33.470 --> 07:35.850] And then, we had to choose one of them. [07:36.010 --> 07:40.030] And then, we could proceed with our analysis of attackers' behavior. [07:40.750 --> 07:46.510] So, you know, that's why I'm saying that the process will be more... [07:47.050 --> 07:48.970] the biggest part of this presentation. [07:49.390 --> 07:53.630] Because we'll take you into our process along with us. [07:53.630 --> 07:56.090] So, first, data collection. [07:56.350 --> 07:59.530] So, just you understand where our data come from. [07:59.530 --> 08:02.670] Because we will be working with different data sets today. [08:02.790 --> 08:05.450] But they all were collected at the same time. [08:06.010 --> 08:10.330] So, Onipods, exposed to the Internet. [08:10.650 --> 08:13.910] It's more precisely RDP Onipods. [08:13.950 --> 08:15.650] So, Remote Desktop Protocol Onipods. [08:15.850 --> 08:19.510] And our very cool interception tool called PyRDP. [08:20.190 --> 08:21.430] Maybe you've heard of it. [08:21.430 --> 08:25.050] It's an open-source tool that you can all use. [08:25.050 --> 08:27.130] If you want, I will not read all that. [08:27.270 --> 08:29.830] I'll just point out the important things for today. [08:30.030 --> 08:31.730] So, it is a monster in the middle. [08:32.730 --> 08:35.730] Its primary use is that. [08:35.930 --> 08:42.230] It has been developed to intercept information before and after compromission of our servers. [08:43.170 --> 08:50.110] So, before compromission, the tool will capture the net NTLM ashes images of every attempt logging to our system. [08:51.410 --> 08:53.330] And we will come back to this point. [08:53.630 --> 08:55.130] Because it also... [08:55.130 --> 08:58.570] Just to show you the cool capacities of this tool. [08:58.770 --> 09:04.430] It also records under video output what is going on in the session after compromission. [09:04.650 --> 09:07.090] So, I wanted to show you right here. [09:07.270 --> 09:07.350] Okay. [09:07.550 --> 09:08.290] This is our tool. [09:08.510 --> 09:09.410] Our replay tool. [09:09.410 --> 09:14.310] So, you'll see the screen of the attacker of like what is going on on our computer. [09:14.610 --> 09:17.610] You'll see the mouse movement with the yellow dot there. [09:17.810 --> 09:22.850] And at the bottom, you'll see everything that goes through the clipboard to the keyboard. [09:23.190 --> 09:29.550] And at the beginning of the session, like right now, you see the information that they use to enter. [09:29.550 --> 09:32.410] So, they use our information administrator admin. [09:32.650 --> 09:34.670] You understand that we want to study attacker. [09:34.670 --> 09:38.310] So, our credentials are very, very easy to guess. [09:39.210 --> 09:42.390] So, you see that our clipboard... [09:42.390 --> 09:44.890] In the clipboard data, there was our IP address. [09:45.430 --> 09:48.330] You see there's something typing on the screen. [09:48.330 --> 09:49.870] And you see it at the bottom too. [09:49.990 --> 09:53.950] Which is very useful when we don't see what is going on on the screen. [09:53.950 --> 09:58.570] When they try to change the password, you can see it at the bottom. [09:58.570 --> 10:00.530] So, it's very useful for our analysis. [10:00.910 --> 10:02.230] Here, very interesting. [10:02.530 --> 10:04.470] The person just paste their C drive. [10:04.470 --> 10:07.370] Which allow us to just grab all the files that are there. [10:09.570 --> 10:13.810] And now they proceed with their activity, which is crypto mining in this case. [10:14.630 --> 10:18.850] So, it's basically like surveillance cameras for Windows system. [10:19.130 --> 10:20.510] So, it's cool to analyze. [10:21.930 --> 10:22.910] But now... [10:22.910 --> 10:24.490] So, this was after compromission. [10:24.670 --> 10:25.290] We get that. [10:25.290 --> 10:29.290] But now we will focus more on before compromission. [10:29.470 --> 10:30.730] On attempt logins. [10:31.690 --> 10:31.830] Okay? [10:32.050 --> 10:37.790] And the way they try to enter in our RDP on IPOTS is by brute forcing. [10:38.050 --> 10:44.990] So, they try just as many credential combinations as they can to try to enter. [10:45.190 --> 10:48.790] And it usually means many attempt logins per second. [10:49.790 --> 10:52.710] So, with that, we collect a lot of data. [10:53.130 --> 10:57.990] And this is from May 2019 to May 2024. [10:58.050 --> 11:00.070] So, five years of data. [11:00.270 --> 11:06.110] There was 57 million attempt logging during this period. [11:06.350 --> 11:07.390] So, sometimes our... [11:07.390 --> 11:09.290] Like our on IPOTS are on and off. [11:09.450 --> 11:10.410] And sometimes there are three. [11:10.530 --> 11:11.150] Sometimes there are one. [11:11.330 --> 11:11.810] It's just... [11:11.810 --> 11:14.350] But they were there since May 2019. [11:15.190 --> 11:15.530] Yeah. [11:16.810 --> 11:26.070] So, from those data, we wanted to study the behavior of the attacker, their strategies, their decision-making in relation to their country of origin. [11:27.210 --> 11:29.630] So, we need to study the proxies. [11:31.910 --> 11:32.410] All right. [11:32.790 --> 11:37.770] So, in this section, I'll be going over how we studied the proxies that Andrea just said. [11:38.870 --> 11:41.230] So, there are multiple ways of studying proxies. [11:41.370 --> 11:42.210] But the main... [11:42.210 --> 11:42.910] Yeah. [11:42.970 --> 11:45.710] The main way is to analyze the traffic. [11:46.330 --> 11:49.970] So, you look at the packets and you figure out if they're using a proxy or not. [11:50.110 --> 11:52.510] However, in our case, we just have the IP address. [11:52.510 --> 11:55.150] So, it's a bit tougher to see if they are using a proxy. [11:56.590 --> 12:02.210] So, one way to analyze this based on the IP address is to... [12:02.810 --> 12:05.390] through the proxy detection services that exist. [12:05.690 --> 12:07.650] So, they are mostly APIs. [12:07.670 --> 12:11.910] So, you send them the IP address and they return whether it's a proxy or not. [12:13.270 --> 12:15.490] So, how do these APIs work? [12:15.670 --> 12:19.310] There are multiple ways, but I'll be going over a few of them just to give you an idea. [12:19.890 --> 12:21.970] The first way is through internal databases. [12:21.970 --> 12:33.090] So, the services have their own database that they maintain every time, for example, the VPN provider updates like a new IP range of IP address that they use as a VPN. [12:33.350 --> 12:39.890] Then, they'll update the internal database and then that's how the information gets transmitted. [12:40.490 --> 12:42.330] Another way is through geolocation. [12:42.610 --> 12:49.970] So, if the IP address is located right next to like a very known VPN hub, then chances are that that IP address is also a VPN. [12:50.410 --> 12:52.230] So, that's how it will be flagged. [12:52.410 --> 12:54.770] Another way is through reverse DNS lookup. [12:54.910 --> 13:02.570] For example, if you look it up and it belongs to like digital ocean, then there are some chances that the IP address is also a proxy. [13:03.390 --> 13:05.050] Again, those are just a few ways. [13:05.210 --> 13:08.250] There are multiple other ways, but just to like give you an idea. [13:12.630 --> 13:17.470] Considering the actual APIs, there are a lot on the Internet and like a lot. [13:17.670 --> 13:19.370] So, how do we choose the right ones? [13:23.650 --> 13:27.190] So, we chose a bit of like diverse tools. [13:27.710 --> 13:30.470] Kind of not randomly, but we chose tools. [13:30.730 --> 13:31.770] Let's just put it that way. [13:31.770 --> 13:34.750] The first one is ipapi.com. [13:34.830 --> 13:36.470] And that one is pretty recent. [13:36.710 --> 13:37.450] So, 2022. [13:37.950 --> 13:39.730] And it's entirely free. [13:40.050 --> 13:42.570] The second one is ipapi.is. [13:43.710 --> 13:45.590] That one is pretty recent as well. [13:45.690 --> 13:47.550] However, it does offer non-free tiers. [13:47.910 --> 13:53.690] So, we might be tricked into thinking that paid services are of like better quality. [13:53.990 --> 13:55.350] We should say that though. [13:55.610 --> 13:58.810] And the last one is ipqualityscore.com. [13:58.950 --> 14:00.170] That one is a bit older. [14:00.170 --> 14:02.530] And again, it offers non-free tiers. [14:03.590 --> 14:04.090] So, yeah. [14:05.170 --> 14:10.170] Concerning the subset of the dataset, obviously, we can't really be... [14:10.170 --> 14:12.190] Okay, we focused only on three months. [14:12.310 --> 14:15.950] So, from July to September of 2022. [14:16.930 --> 14:23.470] The reason being that we had to crack all the passwords for all those sessions and cracking 57 million of passwords. [14:23.690 --> 14:25.150] You don't want to have to do this. [14:25.250 --> 14:27.490] It would be very resource demanding. [14:27.890 --> 14:29.990] So, instead, yeah, that's what we chose. [14:29.990 --> 14:34.830] We still had over 3.4 million of attacks during that range. [14:35.010 --> 14:40.270] Which we narrowed down to only 1,529 unique IP addresses. [14:43.130 --> 14:46.670] For all those attacks, we were able to retrieve three types of information. [14:46.910 --> 14:48.470] The first one being the timestamp. [14:48.710 --> 14:50.250] Then the IP address. [14:50.250 --> 14:52.530] And finally, the credentials tried by the attacker. [14:53.690 --> 14:58.590] Putting that through the APIs, these are the results that we got. [14:58.590 --> 15:00.590] So, I was really confused. [15:00.670 --> 15:04.150] Because why is API 1 flagging four times less than API 3? [15:04.310 --> 15:05.850] And this was my honest reaction. [15:08.470 --> 15:08.910] All right. [15:09.350 --> 15:13.430] So, that's when we were like, okay, well, let's try API services and see what's up with that. [15:13.510 --> 15:17.170] Maybe if we pay an actual price, we'll be able to have, like, real information. [15:17.750 --> 15:18.070] Right. [15:18.230 --> 15:19.850] So, the first tool is VirusTotal. [15:20.410 --> 15:27.090] It's mostly known for its, like, IP reputation or file scanning more than its IP... [15:27.730 --> 15:28.430] What is it? [15:28.550 --> 15:29.390] IP repeat... [15:29.390 --> 15:29.610] No. [15:30.230 --> 15:31.150] VPN detection. [15:31.310 --> 15:31.650] There we go. [15:32.230 --> 15:36.390] However, sometimes it does include the VPN tag, which is what we're interested in. [15:36.670 --> 15:39.050] The second tool that we use is NuSTAR. [15:39.190 --> 15:41.730] A bit less known, but still used for the same purpose. [15:43.730 --> 15:47.430] VirusTotal flagged 4% of our IP addresses as proxies. [15:47.430 --> 15:50.070] And for NuSTAR, it was a bit more, 16%. [15:50.730 --> 15:54.050] Putting that into the graph that you guys just saw, we get this. [15:54.730 --> 15:56.350] Still my reaction, not gonna lie. [15:57.750 --> 15:59.450] So, that's when we realized something else. [15:59.590 --> 16:10.710] It's that when an API or a service doesn't flag the IP address as a proxy, it could either mean that it's not a proxy or that there's just not enough information to flag it as a proxy. [16:10.910 --> 16:14.430] So, in other words, the default value is zero. [16:14.430 --> 16:18.790] And unless there is contradicting information, it's gonna be a proxy. [16:19.110 --> 16:20.870] But otherwise, the default is zero. [16:21.810 --> 16:22.050] Right. [16:22.290 --> 16:23.610] So, moving on. [16:23.710 --> 16:27.310] We're like, okay, what if we have a data set of truth to test all the tools that we use? [16:27.890 --> 16:28.510] Oh, wait. [16:28.670 --> 16:30.030] We have a data set of truth. [16:31.810 --> 16:33.350] Next section, the data set of truth. [16:33.350 --> 16:44.570] So, what we explained as the data set of truth is, based on the whole research, when the attackers did get into our systems, we're able to retrieve a bit more information. [16:44.870 --> 16:45.970] So, bear with me. [16:46.430 --> 16:50.310] This is kind of the breakdown or drill down to what the data set of truth is. [16:50.310 --> 16:59.350] Based on the 57 million login attempts, we had 1.7K of successful logins, and only 1.2K had the full info that we needed. [16:59.790 --> 17:06.450] And once we did drop duplicates on that data set, we had 253 unique IP addresses. [17:08.330 --> 17:17.530] As I said, we had a bit more information for all those new IP addresses, including the internal IP address as well as the internal time zone. [17:17.530 --> 17:21.610] So, here we're talking about the stuff from the attackers' computers directly. [17:22.950 --> 17:24.190] So, here's the plan. [17:24.390 --> 17:30.790] We're going to compare the API results with the data set of truth, and then we'll be able to determine what is the brightest source. [17:32.330 --> 17:37.450] So, from the data set of truth, find out what is the proxy, and then compare it to the API results. [17:38.650 --> 17:39.570] How do we do this? [17:39.830 --> 17:43.690] The first way is through external and internal IP address comparison. [17:44.170 --> 17:45.970] So, this is one of the logs that we got. [17:45.970 --> 17:49.290] The external IP, a normal public IP, all good. [17:49.630 --> 17:51.910] The internal IP, a private one. [17:52.110 --> 17:55.390] So, you know, all those 10.00127.0. [17:55.910 --> 17:58.330] This one is also a private IP. [17:58.590 --> 18:02.630] So, in that case, we had kind of a direct view inside the attacker's network. [18:02.810 --> 18:05.010] So, in that case, we knew that they were not using a proxy. [18:05.550 --> 18:12.350] For another case that we had, it was two public IP addresses, even for the internal one. [18:12.350 --> 18:20.210] So, it's like an IP address hidden by another, sorry, a public IP address hidden by another public IP address. [18:20.390 --> 18:22.790] So, in that case, we knew that they were using a proxy. [18:23.510 --> 18:26.470] The second way is through the time zone analysis. [18:27.070 --> 18:28.670] So, again, an example. [18:29.010 --> 18:31.810] The external IP was located in the U.S. [18:32.470 --> 18:35.130] And it was in, like, UTC minus negative seven. [18:35.670 --> 18:38.470] And then the internal time zone was in Russia, UTC plus six. [18:38.910 --> 18:40.090] Math is not mathing here. [18:40.230 --> 18:41.130] It cannot happen. [18:41.430 --> 18:43.710] So, we knew that they were using a proxy. [18:44.490 --> 18:45.110] And boom. [18:45.210 --> 18:50.710] That's kind of the main ways that we used to see if they were using a proxy or not in the data set of truth. [18:51.730 --> 18:53.750] From there, we could draw some conclusions. [18:54.150 --> 18:56.310] So, we're still in that data set of truth. [18:57.770 --> 18:58.190] Right. [18:58.910 --> 19:05.550] So, we found out that 44% of those 253 IP addresses were proxies. [19:06.650 --> 19:08.690] And putting that into a graph, this is what we get. [19:08.830 --> 19:10.650] So, here, there are two types of information. [19:10.650 --> 19:17.410] The first one being that we can see that the U.S. tend to attack us a lot more than Russia or Algeria or India. [19:17.790 --> 19:24.370] But, however, the U.S. also uses a lot of proxies that are close to them. [19:24.430 --> 19:28.670] In comparison to, for example, India where the rate is more closer to zero. [19:30.810 --> 19:31.290] Alright. [19:31.390 --> 19:33.610] So, this is the location of the attackers. [19:34.270 --> 19:38.670] So, we can see that the proxies that Vietnam use tend to be... [19:41.230 --> 19:41.710] Sorry. [19:43.330 --> 19:47.570] So, we can see that the proxies are mostly located in Vietnam, Iran, and the U.S. [19:48.210 --> 19:50.250] And finally, Morocco and India. [19:50.790 --> 19:56.830] So, one conclusion that could be drawn for this is that people tend to use proxies not far from them. [19:57.450 --> 20:07.550] One reason being that they might not really care to, like, be hidden and, like, pass as a stranger from the other side of the world, but might care more about the speed. [20:07.690 --> 20:12.370] Because, obviously, the closer the proxy is to you, the, like, faster the connections will be. [20:12.690 --> 20:13.470] So, there we go. [20:14.770 --> 20:21.390] Taking a closer look at the trends of proxy usage per country, we can see that Iran is kind of... [20:21.770 --> 20:28.590] We can see that Iran is using about half proxies close to them and half proxies far from them. [20:28.790 --> 20:33.750] If you take a deeper look at the proxies close to them are Iran, Russia, and Turkey. [20:34.010 --> 20:40.530] And the proxies far from them are Canada, Poland, Finland, UK, and finally in Germany. [20:41.450 --> 20:45.430] And if we... if you want, like, just another example, Russia. [20:45.710 --> 20:48.570] We can see that the proxies close to them are Czechia and Russia. [20:48.970 --> 20:53.490] And far from them, we are talking about Australia, Chile, Norway, Germany, and the U.S. [20:53.870 --> 20:59.870] So, one thing that... what conclusion that could be made is that they might share... [20:59.870 --> 21:03.890] Like, Russia and Iran might share the same, like, strategies. [21:04.230 --> 21:05.650] But, and Jordan will talk about this more later. [21:07.050 --> 21:11.710] All right, so now that we have the data set of truth, we are able to compare the results. [21:11.970 --> 21:13.530] So, this is what we'll be going over. [21:13.790 --> 21:17.550] So, IPI results compared to the data set of truth to find what is the best source. [21:18.250 --> 21:24.790] However, remember, we can't use the lines for when the proxy is zero, because that means that... that could mean two things. [21:24.970 --> 21:27.970] One, that it's not a proxy, or a second of all, that it's... [21:27.970 --> 21:29.890] we just don't have enough information. [21:30.070 --> 21:34.290] So, instead, we'll be focusing on the proxy... when the proxy are flagged as one. [21:34.630 --> 21:36.230] That way, we can... we have two cases. [21:36.230 --> 21:41.950] Either the proxy... like, the IP address really is a proxy, or the IP address is not a proxy. [21:42.190 --> 21:43.610] So, true and false positive. [21:44.830 --> 21:45.670] Positive, sorry. [21:46.430 --> 21:48.310] Putting that into a graph, we get this. [21:48.950 --> 21:50.030] Bear with me, it's gonna be okay. [21:50.530 --> 21:51.010] Okay. [21:51.450 --> 22:01.230] So, we can see in that graph that virus total is the most accurate tool, because 94.12% of all the IP addresses it flagged were actually proxies. [22:02.230 --> 22:05.710] However, it also did not flag a lot of IP addresses. [22:06.070 --> 22:08.330] So, like, it's really quality over quantity here. [22:08.650 --> 22:13.710] However, API 3 flagged a lot more IP addresses, but... [22:13.710 --> 22:14.710] Oh, sorry. [22:14.910 --> 22:18.670] Only 78.33% were actually proxies. [22:18.790 --> 22:21.350] So, the accuracy scores are within... on the side. [22:22.790 --> 22:25.570] This is when we had to make a big research decision. [22:26.010 --> 22:29.410] What do we keep as a proxy, and what do we not keep as a proxy? [22:30.650 --> 22:31.750] This is our decision. [22:32.110 --> 22:33.630] A proxy would be... [22:33.630 --> 22:42.110] Like, an IP address would be considered a proxy, if at least virus total, or new store, or the third API, would flag it as a proxy. [22:42.970 --> 22:49.130] So, now we'll be going back to the subset of three months that we talked about before, and doing some analysis concerning this. [22:51.410 --> 23:13.330] So, now that I have my... the truth... or no, the good source of information to be able to cross this variable as presence of proxy or not, with the other variable of my dataset, I can proceed to the analysis of attackers' behavior, and try to study this information, [23:13.670 --> 23:18.450] to study proxy use, in relation to all the other variables that we have. [23:19.110 --> 23:30.830] So, in our three months subset that we concentrated on, there was 42% that were flagged as proxies. [23:33.650 --> 23:40.830] So, the first... the first aspect that I wanted to study is the sophistication of attackers, or more the specific... [23:41.370 --> 23:42.790] one specific strategies, okay? [23:43.130 --> 23:51.790] When I look at the most common username in logging attempt of this dataset, you see that we get a lot of, like, variation of the word administrator, right? [23:52.170 --> 23:55.550] But we also see some very weird information here. [23:56.390 --> 24:06.390] OffshoreBank EC2 AMAZ, which is, in fact, OffshoreBank our RDP certificate name, and EC2 AMAZ being our host name. [24:07.470 --> 24:19.910] So, we understand that they look for our information about our servers before... and leverage this information against us to try to enter, to brute force, okay? [24:20.530 --> 24:24.610] There's also whatoptime.com, where I was surprised. [24:24.610 --> 24:27.070] I had to look up what it was. [24:27.170 --> 24:28.430] I didn't know about this. [24:28.430 --> 24:31.070] And it has to do with our cloud provider. [24:31.350 --> 24:39.930] So, whatoptime is a template that people can download to install Microsoft Windows operating system on DigitalOcean Droplet. [24:40.170 --> 24:44.330] So, you cannot do it, like, within conventional way or method. [24:44.550 --> 24:49.550] So, you guessed it, we are on DigitalOcean to host our Onnipot. [24:49.550 --> 24:53.710] But just, I'll do a small aparte for the geek here. [24:53.910 --> 24:55.110] I bet there's a few of you. [24:56.030 --> 24:58.550] So, this is like the structure of our Onnipot. [24:59.330 --> 25:07.150] Our RDP system and interception tool was deployed on Linux first, and is hosted on DigitalOcean server. [25:07.410 --> 25:14.450] However, the interception tool tunnels to a real Windows machine that is, in fact, hosted on AWS. [25:15.110 --> 25:22.490] So, you understand that the attacker assumed that we might use whatoptime.com to install Windows system on DigitalOcean. [25:22.990 --> 25:26.270] They were wrong, but it was a good guess. [25:26.410 --> 25:33.830] So, what we learned from this is the fact that they use our information. [25:33.830 --> 25:37.810] They look for our information and use it against us. [25:37.970 --> 25:39.810] So, this was for the most common username. [25:40.110 --> 25:43.270] If we look at the most common passwords now, same. [25:43.630 --> 25:47.190] So, well, there's three big trends here. [25:47.370 --> 25:51.550] So, the variation of our RDP certificate is still there in the password. [25:51.770 --> 25:57.890] They also use variation of the word password and use symbol chain of number 10 or less. [25:57.890 --> 26:05.230] So, they use mostly weak passwords to try to enter, or they leverage our information. [26:08.270 --> 26:20.050] So, now, these strategies of targeting us, if we look at the countries it is coming from, this is what we get. [26:20.210 --> 26:23.830] So, these strategies come from countries in this graph. [26:23.830 --> 26:30.530] However, if I put my variable about proxies, which one of those are using proxies? [26:30.750 --> 26:32.470] Well, they are in yellow here. [26:32.650 --> 26:42.670] So, those at the left are all proxies, and this strategy was used mostly by, well, entirely by Hong Kong and Russia. [26:44.410 --> 27:00.490] So, and the fact that there's only two countries there indicate, well, give us a hint that they might be sharing some tools together because they were able to, you know, collect our information and use it against us. [27:01.450 --> 27:15.090] So, you know, it has been documented before that China and Russia are collaborating on cyber crime aspect or, you know, cyber warfare. [27:16.790 --> 27:21.570] And here is just another hint to help jump to this conclusion. [27:21.870 --> 27:23.670] But, you know, we just have that. [27:25.150 --> 27:30.130] The other aspect that we wanted to look at was the length of password. [27:31.190 --> 27:36.310] So, if we compare proxy users versus non-proxy users, this is what we get. [27:36.490 --> 27:39.010] We see, like, the red line is no proxy. [27:39.250 --> 27:40.470] The blue line is proxy. [27:40.690 --> 27:50.250] So, we see that non-proxy users tend to use shorter password when they try to attack us. [27:52.330 --> 27:55.150] After that, the use of popular data leak. [27:55.290 --> 27:58.010] You probably all know about RockU 2021. [27:58.010 --> 28:06.050] It's like the 8.4 billion lines of credential of all the data leaks that are known. [28:07.310 --> 28:17.170] So, we crossed the password that they were trying, that they were using in the attempt login with this big data leak. [28:17.770 --> 28:20.010] And this is what we get. [28:20.150 --> 28:27.810] So, there is a slightly higher probability for non-proxy users to be also using popular credential leak. [28:27.810 --> 28:29.150] Like RockU 2021. [28:29.710 --> 28:32.590] So, the password they were using were inside this database. [28:33.250 --> 28:35.150] When compared to proxy users. [28:38.610 --> 28:40.670] This is why I'm mentioning it. [28:41.790 --> 28:44.110] Another aspect is the number of attacks. [28:44.190 --> 28:46.750] So, the aggressiveness of the attacker. [28:46.750 --> 28:53.110] So, we consider the number of attacks per day on our Unipod. [28:53.290 --> 28:56.710] So, a small attacker would be less than 50 attacks a day. [28:57.470 --> 29:00.730] Aggressive attacker would be more than 700 attacks a day. [29:00.850 --> 29:03.590] And the average would be like everything in between. [29:04.410 --> 29:09.330] So, when comparing the behavior of attackers who use proxy versus not. [29:09.850 --> 29:13.070] There is no significant difference between the two. [29:13.310 --> 29:16.830] So, proxy users are not more aggressive than non-proxy users. [29:17.210 --> 29:18.990] So, basically there is no result here. [29:19.150 --> 29:22.450] But still, in research we say that no result is a result. [29:22.650 --> 29:23.550] So, here it is. [29:25.050 --> 29:28.470] This range of IP address come from Panama. [29:28.950 --> 29:35.810] And I just wanted to show you the different level of aggressiveness coming from the same country. [29:35.830 --> 29:40.750] So, you see that they just have different behavior in terms of attack rate. [29:41.010 --> 29:47.070] So, it just shows the diversity of behavior within the same country. [29:47.350 --> 29:53.530] This is why probably we get insignificant results when we try to compare the countries with this data. [29:53.530 --> 29:58.330] The attackers from a country are not acting as one country against the other. [29:58.530 --> 30:00.150] But like everyone for themselves. [30:01.530 --> 30:04.490] So, our research is not without limits. [30:04.750 --> 30:05.670] I love claviardage. [30:05.850 --> 30:06.710] So, this is my part. [30:08.190 --> 30:13.370] First, jump over host will not be detected in our research. [30:13.490 --> 30:21.310] It means that if we flagged someone as not using proxy. [30:21.310 --> 30:31.250] So, the absence of proxy does not necessarily mean that it is the real origin of the attacker. [30:31.750 --> 30:34.490] But rather that it is a compromised computer. [30:34.650 --> 30:36.450] That this one is not using a proxy. [30:36.610 --> 30:37.670] I'll show you. [30:37.790 --> 30:39.630] Maybe visually it will be better. [30:39.830 --> 30:43.890] So, here is an example from the session we recorded. [30:43.890 --> 30:49.130] So, the person is already into our RDP in our system. [30:49.310 --> 30:53.890] And then they will connect to another remote desktop protocol of another computer. [30:54.130 --> 30:54.430] Right? [30:54.710 --> 31:00.490] And will just perform their activities through there. [31:00.630 --> 31:03.150] They are here brute forcing like other computers. [31:03.750 --> 31:10.290] So, they use our computer to go on another one. [31:11.530 --> 31:16.510] So, in this case, it will be flagged as not using a proxy. [31:16.750 --> 31:19.870] But in fact, they are using a proxy computer. [31:20.290 --> 31:20.810] Are you following? [31:23.170 --> 31:27.430] So, jump over host will not be considered in our analysis. [31:27.430 --> 31:27.790] Right? [31:28.130 --> 31:31.730] Also, it was not possible to distinguish the different type of proxies. [31:31.790 --> 31:36.370] That's why we give this big definition including everything. [31:36.630 --> 31:41.850] Because the tools we use were not allowing us to do this difference. [31:42.210 --> 31:45.170] So, VPN is considered the same thing as data center. [31:45.350 --> 31:48.990] Or using anonymity network or a compromised computer. [31:49.750 --> 31:57.330] And finally, our analysis is limited to the proxy detector that we choose to analyze. [31:57.330 --> 31:57.610] Right? [31:57.730 --> 31:59.390] And we could not analyze them all. [31:59.510 --> 32:01.010] So, it's limited to that. [32:01.450 --> 32:02.890] So, what have we learned? [32:06.330 --> 32:06.770] Alright. [32:07.070 --> 32:15.050] So, the first takeaway that we could draw from all this research is that APIs don't really seem to have a cleaning service for their internal database. [32:16.190 --> 32:27.090] So, what I mean by this is that either the API is too recent and therefore there is a lack of information because they haven't had the time to flag all the IP addresses in the world. [32:27.090 --> 32:30.730] Or either the API is too old. [32:30.750 --> 32:32.350] So, it's like not accurate anymore. [32:32.610 --> 32:36.130] And it's too polluted by all the flagging that's been done like in the years prior. [32:36.670 --> 32:44.010] So, one takeaway would be that in case you really need some IP reputation, a middle-aged API could be the way. [32:45.490 --> 32:52.250] Another thing to take into consideration, well, is it worth it for us to pay for an IP detection service? [32:52.670 --> 33:03.710] The answer is it did not really fill up our needs because in the end we weren't able to detect if there were, if it was like a data center or like the real reason of the proxy. [33:04.150 --> 33:08.510] And also, it's good to take to keep in mind that we did not test all the tools. [33:08.710 --> 33:12.130] So, there, like as you saw in some of the slides, there are a lot of the tools. [33:13.710 --> 33:15.550] So, that's one thing to keep in mind. [33:16.550 --> 33:19.810] Some of the tools that we used also had the variable for the abuser score. [33:19.810 --> 33:22.910] So, this is for the third API, IP quality score. [33:23.410 --> 33:27.510] As you can see, it flagged a lot of the IP addresses as not being an abuser. [33:27.650 --> 33:29.810] So, that's the zero mark. [33:30.830 --> 33:34.730] And however, like we do know that they are abuser because obviously they're attacking us. [33:34.850 --> 33:36.450] So, like, why are you lying? [33:38.110 --> 33:39.450] Secondly, we have virus total. [33:39.790 --> 33:40.910] And same thing here. [33:41.070 --> 33:45.870] It flagged 37% of the 1.5k of IP addresses as harmless. [33:47.470 --> 33:48.770] They were attacking us. [33:48.770 --> 33:49.890] Because we knew they were not harmless. [33:50.510 --> 33:58.770] So, please, like, in case you're using those tools, please, like, take all the results with a grain of salt. [33:58.970 --> 34:09.650] But, however, if you do know of a tool that might meet our interest or if you have any insights concerning this, we'll be happy to hear it once the presentation is over. [34:12.770 --> 34:24.010] The other conclusion that we can have here is that in terms of cyber warfare, it has been documented, I talked about it already, that China and Russia might be collaborating on some things. [34:24.510 --> 34:31.810] So, well, here we have a little bit more evidence of this, at least for, like, information sharing. [34:33.470 --> 34:38.430] So, and the other thing is that, like, I'm speaking from experience. [34:38.430 --> 34:40.830] Have you ever put an Onipot in Russia? [34:41.110 --> 34:42.250] It's kind of hard. [34:42.630 --> 34:43.270] Well, yeah. [34:43.470 --> 34:44.670] An Onipot or a server. [34:44.830 --> 34:45.350] Just a server. [34:45.830 --> 34:46.050] Yes. [34:46.910 --> 34:48.530] Not necessarily an Onipot. [34:48.530 --> 34:51.930] But just having servers over there is quite hard. [34:52.270 --> 34:53.350] Same for China. [34:53.590 --> 35:00.990] But, so, China and Russia has enormous control on whatever servers is on their territory. [35:01.510 --> 35:09.010] So, based on my experience, the fact that Ireland has proxy in Russia is highly, like, surprising. [35:09.010 --> 35:14.630] So, it points toward the fact that they might be sharing some infrastructure here. [35:15.410 --> 35:18.350] But, you know, based on the limited analysis we did. [35:18.770 --> 35:30.810] The second thing, we saw that was very specific, like, the very specific strategies of targeting us was used only by China and Russia. [35:30.810 --> 35:35.330] Again, here, sharing of information or hacking tools, maybe, is happening. [35:37.810 --> 35:40.310] So, the Onipot, we didn't mention, sorry for that. [35:40.470 --> 35:42.090] But the Onipot is in the United States. [35:42.250 --> 35:43.050] It's not in Canada. [35:43.730 --> 35:48.550] And the United States is highly represented in our list of attackers. [35:48.810 --> 35:49.670] So, why is that? [35:50.470 --> 35:51.350] There is... [35:51.350 --> 35:52.530] There are two hypotheses. [35:52.790 --> 35:53.970] So, the first one, we... [35:53.970 --> 35:59.510] As we said, the fact that the attacker might use compromised computers cannot be controlled in this study. [35:59.510 --> 36:05.990] So, and researchers demonstrated that in the U.S., but not only in the U.S., but more in the... [36:06.490 --> 36:15.050] In general, in developed countries, we are more exposed to cyber attacks in those countries. [36:15.130 --> 36:16.530] And it's logical. [36:16.710 --> 36:17.550] Like, there's more people. [36:17.750 --> 36:19.510] There's higher digital literacy. [36:19.810 --> 36:21.410] There's more computer users. [36:21.410 --> 36:23.410] So, there's more potential victims. [36:23.870 --> 36:27.070] So, we are more targeted or exposed. [36:27.070 --> 36:30.230] So, they could be... [36:30.230 --> 36:36.610] This over-representation could be due to a compromised computer instead of real origin of the attacker. [36:36.830 --> 36:38.590] But I have a second hypothesis. [36:39.070 --> 36:47.230] In one of our previous research about RDP compromise session, we saw that some people know how to act clearly. [36:47.490 --> 36:54.450] They enter, they compromise the system, they do a little reconnaissance, and then they change the password and leave. [36:54.450 --> 36:59.790] And others enter and do very weird stuff. [36:59.930 --> 37:04.590] They enter with a changed password that were changed in a previous session. [37:04.750 --> 37:09.790] And they just check their email, look at... [37:11.170 --> 37:16.750] Or do very weird Google search or watch porn, things like that. [37:16.750 --> 37:18.990] So, they do not look like... [37:19.330 --> 37:23.710] They do not have the same behavior as those who look like they know what they are doing. [37:24.070 --> 37:30.430] And so, there was hint of, you know, RDP access reselling there. [37:30.590 --> 37:33.150] And we also see that on the dark web. [37:33.550 --> 37:36.070] This reselling is very much present. [37:38.670 --> 37:50.670] So, there might be some attackers from the United States who are not thinking in terms of cyber warfare, but rather just thinking in terms of making the end meets at the end of the month and try to resell RDP access. [37:50.830 --> 37:51.150] I don't know. [37:51.470 --> 37:58.010] But, you know, just keeping in mind that not everything is about a question of warfare and like a country against another. [37:59.130 --> 38:02.550] That's why, again, the United States might be over-represented here. [38:03.090 --> 38:05.230] So, the next step in our research will be... [38:05.230 --> 38:06.190] I'll conclude with that. [38:06.310 --> 38:22.930] It will be to study more specifically the compromise session and to look at the type of crime that is committed on those sessions in relation to their geographic location and being sensitive or sensible to the proxy use. [38:23.110 --> 38:26.790] So, maybe you will see us again for another story one day. [38:27.350 --> 38:28.050] Thank you. [38:35.310 --> 38:37.190] So, we have time for questions, right? [38:37.450 --> 38:37.610] Yeah. [38:37.970 --> 38:38.050] Okay. [38:38.090 --> 38:38.310] Yes. [38:43.910 --> 39:00.490] So, the first reason I would say you mentioned it, the fact that there might be a more compromised computer than what we expected, or not that we not expected that, but this could explain the fact that they are not using proxy, but in fact they are. [39:01.770 --> 39:13.850] And the second thing is that, through my research from the last couple of years, I saw that malicious hackers are not necessarily as good as we think they are. [39:15.170 --> 39:23.590] And there's research in criminology, by the way, about that, saying that ethical hackers are way more intelligent and better than malicious hackers. [39:23.590 --> 39:25.250] So, maybe that's why you have jobs. [39:26.130 --> 39:26.690] So, maybe that's why you have jobs. [39:26.690 --> 39:33.330] But, yeah, this could be like the other possibility that I see through this experience. [39:35.350 --> 39:49.890] So, this analysis will be biased, it would be tautological, because I consider them more sophisticated, and we could have a debate on the word sophisticated, I just didn't find another better word, because they were targeting us. [39:50.090 --> 39:54.490] So, because I consider them sophisticated, I could not see them otherwise. [39:54.490 --> 40:05.100] So, yeah, I didn't present it today, but there was... [40:06.300 --> 40:17.880] So, the question was, did we do some research about, like, the specific username used in the different country? [40:18.120 --> 40:23.560] Like, I know what the answer of the question is, but I can't remember the question exactly. [40:23.560 --> 40:38.020] But, so, we did not in this research project, but in a previous research project, we look at the specialization of the use of certain username compared to the country of origin. [40:38.260 --> 40:40.480] And there was some things like that. [40:40.800 --> 40:47.160] So, like, the fact that they use our information was one of the conclusion to that. [40:47.160 --> 40:58.560] But there are... I remember that there was also ADM, which is, like, the smaller term for administrator, that was used only by Nicaragua for some reason. [40:58.740 --> 41:01.780] So, there was something there, but I could not find any reason. [41:01.780 --> 41:05.320] So, I did not go more, like, on this subject. [41:05.320 --> 41:13.040] But, yes, there is kind of a certain type of username and password that come from one country only and not the other. [41:14.940 --> 41:26.080] In previous research, I did kind of try to tie script behavior compared to human behavior. [41:26.080 --> 41:28.220] And we find some... [41:28.220 --> 41:35.340] Well, okay, so, the human behavior were more tied to tout out attacks. [41:35.520 --> 41:39.940] Because, you know, it's for sure they all use script because they are attacking us a lot. [41:40.060 --> 41:44.760] Okay, but we could see a certain hint that some attacks were more... [41:44.760 --> 41:48.040] There was a human behind and it was clear. [41:48.040 --> 41:51.040] So, for example, when they start... [41:51.660 --> 41:54.600] So, some of them are just attacking us all the time, right? [41:55.880 --> 42:00.840] And some others are kind of attacking us by blocks of attack. [42:01.060 --> 42:05.700] So, they launch... they seem to be launching an attack and then attacking us, and then it stops. [42:05.900 --> 42:10.740] And then there's a pause, very random, of sometimes many days. [42:10.920 --> 42:13.860] And then they will launch another block of attack. [42:13.860 --> 42:19.020] So, like, when we try to... to crack passwords, we will just try a list. [42:19.160 --> 42:21.840] And then if it's not successful, we just start another list, right? [42:22.020 --> 42:25.950] So, we could see this behavior in the... when we... [42:26.520 --> 42:32.680] I call that calendar attack because I put it on the calendar and we can see, like, for one month. [42:32.880 --> 42:35.160] So, it's highly interesting to see that. [42:35.180 --> 42:38.720] I have, like, another conference... a whole conference on this point, actually. [42:38.920 --> 42:39.840] But, yes, there is. [42:41.300 --> 42:49.100] No, we did... we did not have any... not occurring... originated attack in our data set. [42:49.980 --> 42:52.700] So, I couldn't... [42:52.700 --> 42:54.900] Ah, do... do you want to answer this question? [42:54.960 --> 42:55.960] I'll just repeat the question. [42:56.120 --> 43:02.560] So, are the data set that... the source of information for IP intertwined or not, right? [43:02.700 --> 43:03.340] This is the question. [43:05.340 --> 43:08.060] So, yes, we did see an overlap between all the data sets. [43:08.500 --> 43:14.140] So, API 1, which was the... like, the least flagging API... was here. [43:14.620 --> 43:17.300] And then, API 2 was kind of a... like, similar. [43:17.520 --> 43:20.540] It was... like, the event algorithms were, like, kind of overlapping. [43:20.900 --> 43:26.340] But API 3 would flag all the IP addresses as... yeah, the... [43:26.860 --> 43:29.720] API 1 and 2 were a subset of API 3, basically. [43:30.740 --> 43:36.100] It was... it was kind of hard to see, like, where their data set were coming from, too. [43:36.100 --> 43:40.740] Like, we were constantly... well, it was kind of... not that clear. [43:40.900 --> 43:44.820] So, we could not know exactly where they are taking their information. [43:45.060 --> 43:45.740] So, it was... [43:46.500 --> 43:47.580] We are out of time. [43:47.600 --> 43:52.820] But if you have other questions, it will be a pleasure to answer them on the other side. [43:52.820 --> 43:53.620] Thank you so much. [43:53.920 --> 43:54.540] And this is the second one.