DocumentCode :
1675786
Title :
Botnets Detection Based on IRC-Community
Author :
Lu, Wei ; Ghorbani, Ali A.
Author_Institution :
Fac. of Comput. Sci., Univ. of New Brunswick, Fredericton, NB
fYear :
2008
Firstpage :
1
Lastpage :
5
Abstract :
Botnets are networks of compromised computers controlled under a common command and control (C&C) channel. Recognized as one the most serious security threats on current Internet infrastructure, botnets are often hidden in existing applications, e.g. IRC, HTTP, or Peer-to-Peer, which makes the botnet detection a challenging problem. Previous attempts for detecting botnets are to examine traffic content for IRC command on selected network links or by setting up honeypots. In this paper, we propose a new approach for detecting and characterizing botnets on a large-scale WiFi ISP network, in which we first classify the network traffic into different applications by using payload signatures and a novel clustering algorithm and then analyze the specific IRC application community based on the temporal-frequent characteristics of flows that leads the differentiation of malicious IRC channels created by bots from normal IRC traffic generated by human beings. We evaluate our approach with over 160 million flows collected over five consecutive days on a large scale network and results show the proposed approach successfully detects the botnet flows from over 160 million flows with a high detection rate and an acceptable low false alarm rate.
Keywords :
Internet; invasive software; telecommunication security; IRC channel; IRC command; IRC community; IRC traffic; Internet infrastructure; WiFi ISP network; botnet detection; clustering algorithm; command and control channel; compromised computers; honeypots; network links; network traffic; security threats; Application software; Clustering algorithms; Command and control systems; Communication system traffic control; Computer networks; Internet; Large-scale systems; Payloads; Peer to peer computing; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Telecommunications Conference, 2008. IEEE GLOBECOM 2008. IEEE
Conference_Location :
New Orleans, LO
ISSN :
1930-529X
Print_ISBN :
978-1-4244-2324-8
Type :
conf
DOI :
10.1109/GLOCOM.2008.ECP.398
Filename :
4698173
Link To Document :
بازگشت