News / Events

DFIR Stream 0xA 

"How to Detect when Residential IP Proxies are Used as a Botnet

by Dr. Elisa Chiapponi, Amadeus IT Group.

Abstract: Residential IP Proxies (RESIPs) enable proxying out requests from vast networks of residential devices without inserting any information revealing it. Despite legitimate uses, these proxies have been associated with malicious activities, particularly in the context of web scraping and automated campaigns. In this presentation, we initially describe RESIP networks, presenting the advantages they offer to malicious actors engaging in bot campaigns. Moreover, we show how RESIPs impact traditional bot detection methods. Malicious actors exploit the positive reputation established by genuine users, making it challenging to differentiate between legitimate and malicious activities. To counteract these challenges, we propose our RESIP detection technique based on Round Trip Time (RTT) measurements. We present the successful results obtained from applying this technique in both semi-controlled and real-world scenarios. In the second part of the presentation, we reveal new insights into RESIP inner functioning and modus operandi. We present the similarities and differences of the ecosystems associated with four RESIP providers (geographic distribution, types, and management of machines used). Moreover, we display how the global amount of residential IP addresses leveraged by RESIPs is smaller than what was considered so far, and we propose new directions to build upon the collected information.

About the Speaker

Dr. Elisa Chiapponi is currently a security researcher in the Global Security Operations team of Amadeus IT Group.

She received her BSc in Bioengineering from Universitá degli studi di Pavia in 2017. In 2020, she was granted a double MSc from Télécom Paris (Communication System Security) and Politecnico di Torino (Software Engineering). Dr. Chiapponi obtained her Ph.D. degree in Cryptography and Security from Sorbonne Université in 2023 with a thesis titled "Detecting and Mitigating the New Generation of Scraping Bots". She worked on her research project in the Digital Security Department of EURECOM and at Amadeus IT Group, under the supervision of Prof. Marc Dacier and Dr. Olivier Thonnard. In the spring of 2022 and 2023, she was a visiting researcher at the Resilient Computing and Cybersecurity Center (RC3) of King Abdullah University of Science and Technology.


Dr. Chiapponi's domains of interest and expertise are Network and Application Security, Internet Measurements, Bot Mitigation and Proxy Identification. Her research works have been published in relevant international conferences (among others IEEE/IFIP International Conference on Dependable Systems and Networks, ACM Internet Measurement Conference, and Network Traffic Measurement and Analysis Conference) and recognized with second place at the Cyber Woman Researcher European Award 2023 by CEFCYS.

Date and Time: Tuesday, May 28 · 4:00 – 5:00 pm (GMT+00:00) United Kingdom Time

Location:  Online (Pre-Registration is Required to Obtain the Meeting Link)

Event Registration Link:  https://forms.gle/o4uahrWubmR83m9p7 

Online Registration Ends May 26 at 4:00 PM (GMT+00:00) United Kingdom Time

Visit Us On Social Media:

Subscribe to our Facebook Group
Follow Us On Twitter
Like our Facebook Page