DocumentCode :
2108948
Title :
Framework for Zombie Detection Using Neural Networks
Author :
Salvador, Paulo ; Nogueira, António ; Franca, U. ; Valadas, Rui
Author_Institution :
Inst. de Telecomun., Univ. of Aveiro, Aveiro
fYear :
2009
fDate :
24-28 May 2009
Firstpage :
14
Lastpage :
20
Abstract :
One of the most important threats to personal and corporate Internet security is the proliferation of zombie PCs operating as an organized network. Zombie detection is currently performed at the host level and/or network level, but these options have some important drawbacks: antivirus, anti-spyware and personal firewalls are ineffective in the detection of hosts that are compromised via new or target-specific malicious software, while network firewalls and intrusion detection systems were developed to protect the network from external attacks but they were not designed to detect and protect against vulnerabilities that are already present inside the local area network. This paper presents a new approach, based on neural networks, that is able to detect zombie PCs based on the historical traffic profiles presented by "licit" and "illicit" network applications. The evaluation of the proposed methodology relies on traffic traces obtained in a controlled environment and composed by licit traffic measured from normal activity of network applications and malicious traffic synthetically generated using the subseven backdoor. The results obtained show that the proposed methodology is able to achieve good identification results, being at the same time computationally efficient and easy to deploy in real network scenarios.
Keywords :
Internet; invasive software; local area networks; neural nets; telecommunication traffic; corporate Internet security; historical traffic profiles; illicit network application; licit network application; local area network; malicious software; neural networks; personal Internet security; subseven backdoor; zombie PC; zombie detection; Communication system traffic control; Electronic mail; IP networks; Intrusion detection; Local area networks; Neural networks; Personal communication networks; Protection; Telecommunication traffic; Unsolicited electronic mail; Zombie; botnet; illicit traffic; neural network;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Internet Monitoring and Protection, 2009. ICIMP '09. Fourth International Conference on
Conference_Location :
Venice/Mestre
Print_ISBN :
978-1-4244-3839-6
Electronic_ISBN :
978-0-7695-3612-5
Type :
conf
DOI :
10.1109/ICIMP.2009.10
Filename :
5076342
Link To Document :
بازگشت