DocumentCode :
1971313
Title :
Honeypot-Aware Advanced Botnet Construction and Maintenance
Author :
Zou, Cliff C. ; Cunningham, Ryan
Author_Institution :
Sch. of Electr. Eng. & Comput. Sci., Central Florida Univ., Orlando, FL
fYear :
2006
fDate :
25-28 June 2006
Firstpage :
199
Lastpage :
208
Abstract :
Because "botnets" can be used for illicit financial gain, they have become quite popular in recent Internet attacks. "Honeypots" have been successfully deployed in many defense systems. Thus, attackers constructing and maintaining botnets are forced to find ways to avoid honeypot traps. In this paper, we present a hardware and software independent honeypot detection methodology based on the following assumption: security professionals deploying honeypots have liability constraints such that they cannot allow their honeypots to participate in real (or too many real) attacks. Based on this assumption, attackers can detect honeypots in their botnet by checking whether the compromised machines in the botnet can successfully send out unmodified malicious traffic to attackers\´ sensors or whether the bot controller in their botnet can successfully relay potential attack commands. In addition, we present a novel "two-stage reconnaissance" worm that can automatically construct a peer-to-peer structured botnet and detect and remove infected honeypots during its propagation stage. Finally, we discuss some guidelines for defending against the general honeypot-aware attacks
Keywords :
Internet; computer crime; invasive software; peer-to-peer computing; Internet attack; botnet maintenance; honeypot detection methodology; honeypot-aware advanced botnet construction; peer-to-peer structured botnet; Automatic control; Computer crime; Computer networks; Computer science; Computer security; Computer worms; Hardware; Internet; Relays; Viruses (medical);
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks, 2006. DSN 2006. International Conference on
Conference_Location :
Philadelphia, PA
Print_ISBN :
0-7695-2607-1
Type :
conf
DOI :
10.1109/DSN.2006.38
Filename :
1633509
Link To Document :
بازگشت