Mirai Flashcards
1
Q
What is Mirai?
A
- IoT botnet which first appeared in 2016
- Actively scans the network and propagates to any vulnerable devices it finds
2
Q
Why is Mirai possible?
A
- Vulnerabilities
- Weak credentials
- Poor network management
- Always online
3
Q
Process Mirai
A
- Scan
- Report IP + credentials to Listener Server
- Add new device to Loader Server
- Load
- Recruited
- Send command to C&C server
- Dispatch command
- Attack
4
Q
Mirai Mitigation
A
- Limit exposure to external adversaries
-> Firewalls, NAT
-> Close open ports not needed for functionality - Ensure correct security configuration
- Remove device vulnerabilities
-> Apply security patches
5
Q
Mirai Detection
A
- Signature-based intrusion detection
-> System monitors communications or device behavior for known patterns of attack
-> Fast and reliable, widely deployed - Anomaly-based intrusion detection
-> Detects deviations from normal behavior as anomalies
-> Able to detect also previously unknown attacks
6
Q
Mirai Recovery
A
- Network isolation
-> Traffic filtering rules used to isolate infected device from others
-> Prevent further injections in the network
-> Prevent device from attacking remote victims - Reset device