Residential IP Proxy (RESIP) service provides a proxy server running on hosts in residential networks. However, RESIP services are suspected of being used illegal purposes, as reported by Mi et al. in 2019. Triggered by this research, many investigations into the malicious use of RESIP services have been undertaken. However, most of these studies have been limited to investigating just the actual communications initiated by various RESIP clients, with information about the RESIP clients’ general patterns of behavior remaining unknown. In this paper, we investigate four major RESIP providers, Bright Data, ProxyRack, Oxylabs, and Proxy-Seller, and observe the traffic patterns for various RESIP hosts. We identify and discuss some potential malicious behaviors in the use of these RESIP services, based on an analysis of the communication metadata.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Honey-Proxy: Revealing Malicious Activities via Residential Proxies

  • Hiroaki Kikuchi,
  • Ryuichi Moriya,
  • Takumi Kitahara,
  • Hikari Fukuda

摘要

Residential IP Proxy (RESIP) service provides a proxy server running on hosts in residential networks. However, RESIP services are suspected of being used illegal purposes, as reported by Mi et al. in 2019. Triggered by this research, many investigations into the malicious use of RESIP services have been undertaken. However, most of these studies have been limited to investigating just the actual communications initiated by various RESIP clients, with information about the RESIP clients’ general patterns of behavior remaining unknown. In this paper, we investigate four major RESIP providers, Bright Data, ProxyRack, Oxylabs, and Proxy-Seller, and observe the traffic patterns for various RESIP hosts. We identify and discuss some potential malicious behaviors in the use of these RESIP services, based on an analysis of the communication metadata.