Bulletproof hosting

Bulletproof hosting (BPH) is technical infrastructure service provided by a web hosting provider that is resilient to complaints of illicit activities, which serves criminal actors as a basic building block for streamlining various cyberattacks.[1] It also includes allowance of the provider for hosting online gambling, illegal pornography, botnet C&C servers, spam, copyrighted materials, hate speech and misinformation, despite takedown court orders, law enforcement subpoenas, allowing such material in acceptable use policy (AUP).[2][3][4] BPH usually operate in jurisdictions which have lenient laws against sanctions of such conducts. Most non-BPH service providers prohibit transferring materials over their network that would be in violation of their terms of service and the local laws of the incorporated jurisdiction, and often times any abuse reports would result in takedowns to avoid their autonomous system's IP block being blacklisted by other providers and by Spamhaus.[5]

Difficulties

Since any abuse reports to the BPH will be disregarded, in most cases, the whole IP block assigned to the BPH's AS will be blacklisted by other providers and 3rd party spam filters. Additionally, BPH also have difficulty in finding network peering points for establishing Border Gateway Protocol sessions, thus toiled to provide stable network connectivity, and in extreme cases, BPH also be completely de-peered;[1] therefore BPH providers evade AS's reputation based fortification such as BGP Ranking and ASwatch through unconventional methodologies.[2]

Web hosting reseller

According to a report, due to increasing perplexity, BPH providers engage in establishing reseller relationships with lower-end hosting providers; although these providers aren't complicit in supporting the illegitimate activities, they rather more often lenient on abuse reports or do not actively engage in fraud detection. Thus BPH conceals behind lower-end hosting providers, leveraging their better reputation and simultaneously operating both bulletproof and legitimate resells through the sub-allocated network blocks.[6] However, if the BPH services got caught, the clients get migrated to a newer internet infrastructure—newer lower-end AS, or IP space—thus effectively making the blacklisted IP addresses of the previous AS ephemeral; thus continuing to engage in criminal conduct by modifying the DNS server's resource records of the listening services and making it point to the newer IP addresses belonging to the current AS's IP space.[7] Customary mode of contact for BPH providers are ICQ, Skype, and XMPP (or Jabber).[8][9]

Admissible abuses

Majority of the BPH providers pledge immunity against copyright infringement and court order takedown notices, notably Digital Millennium Copyright Act (DMCA), Electronic Commerce Directive (ECD) and law enforcement subpoenas, along with allowance for operating phishing, scams (such as High-yield investment program), botnet masters and unlicensed online pharmacy websites. In these cases, the BPH providers (known as "offshore providers") operate in jurisdictions which doesn't have any extradition treaty or mutual legal assistance treaty (MLAT) signed with five eye countries, particularly the United States.[10][11][12] However, most BPH providers have zero-tolerance policy towards child pornography and terrorism, although few allow cold storage of such material given forbidden open-accessibility via the internet.[13]

Prevalent jurisdictions for incorporation and location of the data centers for BPH providers include Russia (being more permissive),[14] Ukraine, China, Moldova, Romania, Bulgaria, Belize, Panama and Seychelles.[15][16]

Impacts

BPH services act as vital network infrastructure providers for activities such as cybercrime and online illicit economies,[17] and the well-established working model of the cybercrime economies surrounds upon tool development and skill-sharing among peers.[18] The development of exploits, such as zero-day vulnerabilities, are done by a very small community of highly-skilled actors, who encase them in convenient tools which are usually bought by low-skilled actors (known as script kiddies), who make use of BPH providers for carry out cyberattacks, usually targeting low-profile unpretentious network services and individuals.[19][20] According to a report produced by Carnegie Mellon University for the United States Department of Defense, low-profile amateur actors are also potent in causing harmful consequences, especially to small businesses, inexperienced internet users, and miniature servers.[21]

Criminal actors also run specialized computer programs on BPH providers knowns as port scanners which scans the entire IPv4 address space for open ports, services run on those open ports, and the version of those service daemons, thus actively scrutinizing for vulnerable versions for exploitation.[22] One such notable vulnerability scanned by the port scanners include OpenSSL Heartbleed, which affected millions of internet servers.[23] Furthermore, BPH clients also host click fraud, adwares (such as DollarRevenue), and money laundering recruitment sites, which lure untried internet users into honey trapping and causing financial losses to the individuals while unrestrictedly keeping their illicit sites online, despite court orders and takedown attempts by the law enforcement.[24]

Notable closed services

The following are some of the notable defunct BPH providers:

See also

References

  1. McCoy, Mi & Wang 2017, p. 805.
  2. Konte, Feamster & Perdisci 2015, p. 625.
  3. Han, Kumar & Durumic 2021, p. 4.
  4. "Host of Internet Spam Groups Is Cut Off". The Washington Post. 12 November 2008. Archived from the original on 22 July 2020. Retrieved 4 December 2021.
  5. Han, Kumar & Durumic 2021, p. 5-6.
  6. McCoy, Mi & Wang 2017, p. 805-806.
  7. McCoy, Mi & Wang 2017, p. 806.
  8. McCoy, Mi & Wang 2017, p. 811.
  9. Goncharov, Max (15 July 2015). "Criminal Hideouts for Lease: Bulletproof Hosting Services" (PDF). Trend Micro. Archived (PDF) from the original on 19 July 2021. Retrieved 5 December 2021.
  10. Leporini 2015, p. 5.
  11. Clayton & Moore 2008, p. 209.
  12. Konte, Feamster & Jung 2008, p. 10.
  13. Kopp, Strehle & Hohlfeld 2021, p. 2432.
  14. Caesar, Ed (27 July 2020). "The Cold War Bunker That Became Home to a Dark-Web Empire". The New Yorker. Archived from the original on 5 October 2021. Retrieved 5 December 2021.
  15. Thomas, Elise (8 August 2019). "Inside the bulletproof hosting providers that keep the world's worst websites in business". ABC News. Archived from the original on 4 September 2021. Retrieved 5 November 2021.
  16. Richardson, Ronny; North, Max M. (1 January 2017). "Ransomware: Evolution, Mitigation and Prevention". International Management Review. Kennesaw State University. 13 (1): 13.
  17. Collier & Hutchings 2021, p. 1.
  18. Collier & Hutchings 2021, p. 1-2.
  19. Bradbury 2010, p. 17.
  20. Collier & Hutchings 2021, p. 2.
  21. Mead, Nancy R.; Hough, Eric; Stehney, Theodore R. (31 October 2005). Security Quality Requirements Engineering (SQUARE) Methodology (Report). Carnegie Mellon University. doi:10.1184/R1/6583673.v1.
  22. Durumeric, Zakir; Bailey, Michael; Halderman, J. Alex (August 2014). An internet-wide view of internet-wide scanning. USENIX conference on Security Symposium. USENIX. p. 65-66.
  23. Heo, Hawnjo; Shin, Seungwon (May 2018). Who is knocking on the Telnet Port: A Large-Scale Empirical Study of Network Scanning. Asia Conference on Computer and Communications Security. p. 625-626. doi:10.1145/3196494.3196537.
  24. Watson, David (2007). "The evolution of web application attacks". Network Security. ScienceDirect. 2007 (11). doi:10.1016/S1353-4858(08)70039-4. ISSN 1353-4858.
  25. Krebs, Brian (28 September 2019). "German Cops Raid 'Cyberbunker 2.0', Arrest 7 in Child Porn, Dark Web Market Sting". Krebs on Security. Retrieved 10 June 2021.
  26. "Major Source of Online Scams and Spams Knocked Offline", The Washington Post, November 2008.
  27. "Security Fix - Russian Business Network: Down, But Not Out". The Washington Post. Retrieved 2016-10-07.
  28. "Scammer-Heavy U.S. ISP Grows More Isolated", The Washington Post, September 2009.
  29. "The Fallout from the 3FN Takedown", The Washington Post, June 2009.
  30. "ISP shuttered for hosting 'witches' brew' of spam, child porn", The Register, May 2010
  31. "Rogue ISP ordered to liquidate, pay FTC $1.08 million", Ars Technica, May 2010.
  32. 'Bulletproof' ISP for crimeware gangs knocked offline, , The Register, May 2010.

Bibliography

This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.