DocumentCode :
2102266
Title :
An analysis model of botnet tracking based on ant colony optimization algorithm
Author :
Wang, Ping ; Wang, Tzu Chia ; Kuo, Pu-Tsun ; Wang, Chin Pin
Author_Institution :
Dept. of Inf. Manage., Kun Shan Univ., Tainan, Taiwan
fYear :
2010
fDate :
16-18 Aug. 2010
Firstpage :
606
Lastpage :
611
Abstract :
Available botnet detection schemes all supposed that ISPs would be cooperative to record or generate the necessary routing information for path reconstruction. In practice, ISP´s service constantly is a mutual benefit for intelligence exchange. Therefore the constraint, require cooperation between ISPs, ought to be relaxed. A new IP traceback scheme based on ant colony optimization (ACO) algorithm is proposed for incomplete routing logs are provided. The aim of our work is to develop an analysis model for reconstruction of attack paths to traceback the botnet C&C via ant-inspired collective intelligence by calculating the pheromone to find possible routes with support and confidence degree. The validation of model uses NS2 (Network Simulator, version2) complied by dark IP map, to simulate the scenario of fake IP attack, to test the effectiveness of model. Furthermore, sensitivity analysis is conducted to investigate significant parameters´ effect on the output of attack paths. Experimental results show that the proposed approach effectively suggests the best attack path of botnet in a dynamic network environment.
Keywords :
optimisation; software agents; ISP service; ant colony optimization algorithm; botnet detection; routing information; sensitivity analysis; Facsimile; Nickel; Botnet; ant colony optimization; attack path;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Networked Computing and Advanced Information Management (NCM), 2010 Sixth International Conference on
Conference_Location :
Seoul
Print_ISBN :
978-1-4244-7671-8
Electronic_ISBN :
978-89-88678-26-8
Type :
conf
Filename :
5573232
Link To Document :
بازگشت