Title of article :
BotRevealer: Behavioral Detection of Botnets based on Botnet Life-cycle
Author/Authors :
Khoshhalpour ، Ehsan - Amirkabir University of Technology , Shahriari ، Hamid Reza - Amirkabir University of Technology
Pages :
7
From page :
55
To page :
61
Abstract :
Nowadays, botnets are considered as essential tools for planning serious cyber attacks. Botnets are used to perform various malicious activities such as DDoS attacks and sending spam emails. Different approaches are presented to detect botnets; however most of them may be ineffective when there are only a few infected hosts in monitored network, as they rely on similarity in bots activities to detect the botnet. In this paper, we present a host-based method that can detect individual bot-infected hosts. This approach is based on botnet life-cycle, which includes common symptoms of almost all types of botnet despite their differences. We analyze network activities of each process running on the host and propose some heuristics to distinguish behavioral patterns of bot process from legitimate ones based on statistical features of packet sequences and evaluating an overall security risk for it. To show the effectiveness of the approach, a tool named BotRevealer has been implemented and evaluated using real botnets and several popular applications. The results show that in spite of diversity of botnets, BotRevealer can effectively detect the bot process among other active processes.
Keywords :
Botnet Detection , Botnet Life , Cycle , Host , Based Intrusion Detection , Heuristic Algorithm
Journal title :
ISeCure, The ISC International Journal of Information Security
Serial Year :
2018
Journal title :
ISeCure, The ISC International Journal of Information Security
Record number :
2454679
Link To Document :
بازگشت