Full Program »
RevProbe: Detecting Silent Reverse Proxies in Malicious Server Infrastructures
We present RevProbe, a state-of-the-art tool for automatically detecting silent reverse proxies and identifying the server infrastructure behind them. RevProbe uses active probing to send requests to a target IP address and analyzes the responses looking for discrepancies indicating that the IP address corresponds to a reverse proxy. We extensively test RevProbe showing that it significantly outperforms existing tools. Then, we apply RevProbe to perform the first study on the usage of silent reverse proxies in both benign and malicious Web services. RevProbe identifies that 12% of malicious IP addresses correspond to reverse proxies, furthermore 85% of those are silent (compared to 52% for benign reverse proxies).
Author(s):
Antonio Nappa
IMDEA Software Institute
Spain
Rana Faisal Munir
Universitat Politecnica de Catalonia
Spain
Irfan Khan Tanoli
Gran Sasso Science Institute
Italy
Christian Kreibich
LastLine & International Computer Science Institute
United States
Juan Caballero
IMDEA Software Institute
Spain