Title of article
Detecting Bot Networks Based On HTTP and TLS Traffic Analysis
Author/Authors
Nafarieh, Zahra Science and Research Branch - Islamic Azad University
Pages
10
From page
61
To page
70
Abstract
Abstract— Bot networks are a serious threat to cyber security, whose destructive behavior affects network performance directly. Detecting of infected HTTP communications is a big challenge because infected HTTP connections are clearly merged with other types of HTTP traffic. Cybercriminals prefer to use the web as a communication environment to launch application layer attacks and secretly engage in forbidden activities, while TLS (Transport Layer Security) protocols allow encrypted communication between client and server in the context of Internet provides. Methods of analyzing traffic behavior do not depend on payloads. This means that they can work with encrypted network communication protocols. Traffic behavior analysis methods do not depend on package shipments, which means they can work with encrypted network communication protocols. Hence, the analysis of TLS and HTTP traffic behavior has been considered for detecting malicious activities. Because of the exchange of information in the network context is very high and the volume of information is very large, storing and indexing of this massive data require a Big data platform.
Keywords
Bot Networks , HTTP Traffic Analysis , TLS Traffic Analysis , Intrusion Detection , Network Security , Security Threats
Journal title
Journal of Advances in Computer Engineering and Technology
Serial Year
2020
Record number
2529853
Link To Document