论文标题
对中国住宅代理的广泛研究
An Extensive Study of Residential Proxies in China
论文作者
论文摘要
我们在中国进行了第一个对住宅代理(RESIPS)的深入特征,在以前的作品中很少研究。我们的研究通过基于语义的分类器使我们的研究成为可能,以自动捕获改写服务。除了分类器外,还确定了新技术以捕获转移而无需与ROSIP服务进行交互和传递流量,这可以大大降低成本,从而可以连续监视转移。我们的repip服务分类器在10倍的交叉验证中的召回率为99.7%,精度为97.6%,取得了良好的表现。应用分类器已经确定了399个改装服务,这是一个更大的集合,而所有以前的作品中收集的38个改装服务。我们为捕获捕获的努力导致收集9,077,278次IPS IPS(51.36%位于中国),其中96.70%在公开可公开的repip数据集中没有覆盖。对救援及其服务进行了广泛的衡量标准,发现了一系列有趣的发现以及一些安全性的影响。尤其是,位于中国的80.05%的IPS的805%的IPS在2021年期间至少有一个恶意交通流,导致5200万恶意交通流总计。在包括政府机构,教育机构和企业在内的559个敏感组织的公司网络中也观察到了持续措施。此外,3,232,698个中国统计IPS已开设了至少一个TCP/UDP端口,用于接受继电器请求,这会给本地的居民网络带来不可忽略的安全风险。此外,中国的91%货币IPS年龄不到10天,而大多数中国货币服务在整个时间的日常活动中都表现出波峰 - 陷入困境的模式。
We carry out the first in-depth characterization of residential proxies (RESIPs) in China, for which little is studied in previous works. Our study is made possible through a semantic-based classifier to automatically capture RESIP services. In addition to the classifier, new techniques have also been identified to capture RESIPs without interacting with and relaying traffic through RESIP services, which can significantly lower the cost and thus allow a continuous monitoring of RESIPs. Our RESIP service classifier has achieved a good performance with a recall of 99.7% and a precision of 97.6% in 10-fold cross validation. Applying the classifier has identified 399 RESIP services, a much larger set compared to 38 RESIP services collected in all previous works. Our effort of RESIP capturing lead to a collection of 9,077,278 RESIP IPs (51.36% are located in China), 96.70% of which are not covered in publicly available RESIP datasets. An extensive measurement on RESIPs and their services has uncovered a set of interesting findings as well as several security implications. Especially, 80.05% RESIP IPs located in China have sourced at least one malicious traffic flows during 2021, resulting in 52-million malicious traffic flows in total. And RESIPs have also been observed in corporation networks of 559 sensitive organizations including government agencies, education institutions and enterprises. Also, 3,232,698 China RESIP IPs have opened at least one TCP/UDP ports for accepting relaying requests, which incurs non-negligible security risks to the local network of RESIPs. Besides, 91% China RESIP IPs are of a lifetime less than 10 days while most China RESIP services show up a crest-trough pattern in terms of the daily active RESIPs across time.