DocumentCode :
1866690
Title :
Scomf and SComI botnet models: The cases of initial unhindered botnet expansion
Author :
Khosroshahy, M. ; Ali, M.K.M. ; Dongyu Qiu
Author_Institution :
Electr. & Comput. Eng. Dept., Concordia Univ., Montreal, QC, Canada
fYear :
2012
fDate :
April 29 2012-May 2 2012
Firstpage :
1
Lastpage :
5
Abstract :
Botnets have become platforms to launch distributed denial-of-service attacks and coordinate massive e-mail spam campaigns, to name just a few of botnet-related nefarious activities. Apart from the wired networks, the increasingly Internet-enabled cellular wireless networks are also vulnerable to botnet attacks; a situation which motivates a thorough study of botnet expansion and the mathematical models thereof. In this paper, we propose the following two Continuous-Time Markov Chain-based models for prediction of the botnet size in the initial phase of botnet lifecycle: SComF for the case of finite number of susceptible nodes (suitable for a botnet expanding in a closed environment such as an administrative domain, or a LAN) and SComI for the case of infinite number of susceptible nodes (suitable for a botnet expanding in the larger Internet). Having access to such models would enable security experts to have reliable size estimates and therefore be able to defend against an emerging botnet with adequate resources. We derive the probability distributions for both models and provide some numerical results as well as a simulation study accompanying the numerical analysis of the SComF model using the GTNetS network simulator.
Keywords :
Internet; Markov processes; cellular radio; computer network security; radio networks; statistical distributions; GTNetS network simulator; Georgia Tech network simulator; Internet-enabled cellular wireless networks; SComF botnet models; SComI botnet models; botnet attacks; botnet expansion; botnet-related nefarious activities; continuous-time Markov chain-based models; distributed denial-of-service attacks; e-mail spam campaigns; probability distributions; Analytical models; Grippers; Mathematical model; Numerical models; Probability distribution; Sociology; Statistics; Analytical models; Botnets; Computer security; Epidemic models; Malware propagation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Electrical & Computer Engineering (CCECE), 2012 25th IEEE Canadian Conference on
Conference_Location :
Montreal, QC
ISSN :
0840-7789
Print_ISBN :
978-1-4673-1431-2
Electronic_ISBN :
0840-7789
Type :
conf
DOI :
10.1109/CCECE.2012.6334871
Filename :
6334871
Link To Document :
بازگشت