Investigating Web Defacement Campaigns at Large
Investigating Web Defacement Campaigns at Large Federico Maggi, Marco Balduzzi, Ryan Flores, Lion Gu, Vincenzo Ciancaglini Forward-Looking Threat Research Team - Trend Micro, Inc. ABSTRACT supporting actors. Over the years, defacers have abandoned their Website defacement is the practice of altering the web pages of a interested in defacing for the mere purpose of advertising the com- website after its compromise. The altered pages, called deface pages, promise, pursuing defacement more as a mean to broadcast strong can negatively affect the reputation and business of the victim site. messages “to the World”—by compromising popular websites. Previous research has focused primarily on detection, rather than Despite several actors are still driven by the desire of promot- exploring the defacement phenomenon in depth. While investigat- ing their own reputation, an increasing number of defacers strive ing several defacements, we observed that the artifacts left by the instead to promote their ideologies, religious orientation, political defacers allow an expert analyst to investigate the actors’ modus views, or other forms of activism, often closely following real-world operandi and social structure, and expand from the single deface events (e.g., war, elections, crisis, terrorist attacks). We refer to this page to a group of related defacements (i.e., a campaign). However, phenomenon as dark propaganda, to highlight that legitimate re- manually performing such analysis on millions of incidents is te- sources are abused for pushing the actors’ viewpoints. For example, dious, and poses scalability challenges. From these observations, we in 2013–2014 “Team System Dz” defaced over 2,800 websites, and 1 propose an automated approach that efficiently builds intelligence planted pro-ISIL/ISIS content to protest against the US military 2 information out of raw deface pages.
[Show full text]