• DocumentCode
    2220844
  • Title

    Entelecheia: Detecting P2P botnets in their waiting stage

  • Author

    Huy Hang ; Xuetao Wei ; Faloutsos, Michalis ; Eliassi-Rad, Tina

  • Author_Institution
    Univ. of California, Riverside, Riverside, CA, USA
  • fYear
    2013
  • fDate
    22-24 May 2013
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    Detecting botnets is a critical need for securing one´s network and the Internet at large. Despite significant efforts, the problem of botnet detection is still unresolved, especially, when one wants to detect: (a) decentralized or peer-to-peer botnets, (b) botnets that are in a non-active period known as the “Waiting” stage, and (c) polymorphic bots that evade signature detection. We propose a graph-based approach called Entelecheia that is aimed at addressing all three challenges above. The inspiration for our work started with the following question: Can we detect botnets by examining long-lived and low-intensity flows? Despite their intuitive appeal, right out of the box solutions produce too many false positives. To make it effective, we propose a graph-based solution that focuses on the “social” behavior of the botnet. Specifically, we introduce: (a) the concept of Superflow, to create a graph of likely malicious flows, and (b) two synergistic graph-mining steps to cluster and label botnet nodes. We conduct extensive experiments using real botnet traces injected into real traffic traces. Our approach, Entelecheia, produces a median F1 score of 91.8% across various experiments and is robust to various setups and parameter values. Entelecheia can be seen as a first step towards a new and more effective way of detecting botnets.
  • Keywords
    Internet; computer network security; data mining; graph theory; pattern clustering; peer-to-peer computing; Entelecheia; Internet; P2P botnet detection problem; botnet social behavior; decentralized botnets; graph-based approach; graph-based solution; long-lived flows; low-intensity flows; malicious flows; median Fl score; peer-to-peer botnets; polymorphic bots; signature detection; synergistic graph-mining steps; waiting stage; anomaly detection; botnet; community; graph-mining; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    IFIP Networking Conference, 2013
  • Conference_Location
    Brooklyn, NY
  • Type

    conf

  • Filename
    6663501