DocumentCode
2353753
Title
Detecting stealthy P2P botnets using statistical traffic fingerprints
Author
Zhang, Junjie ; Perdisci, Roberto ; Lee, Wenke ; Sarfraz, Unum ; Luo, Xiapu
Author_Institution
Georgia Inst. of Technol., Atlanta, GA, USA
fYear
2011
fDate
27-30 June 2011
Firstpage
121
Lastpage
132
Abstract
Peer-to-peer (P2P) botnets have recently been adopted by botmasters for their resiliency to take-down efforts. Besides being harder to take down, modern botnets tend to be stealthier in the way they perform malicious activities, making current detection approaches, including, ineffective. In this paper, we propose a novel botnet detection system that is able to identify stealthy P2P botnets, even when malicious activities may not be observable. First, our system identifies all hosts that are likely engaged in P2P communications. Then, we derive statistical fingerprints to profile different types of P2P traffic, and we leverage these fingerprints to distinguish between P2P botnet traffic and other legitimate P2P traffic. Unlike previous work, our system is able to detect stealthy P2P botnets even when the underlying compromised hosts are running legitimate P2P applications (e.g., Skype) and the P2P bot software at the same time. Our experimental evaluation based on real-world data shows that the proposed system can achieve high detection accuracy with a low false positive rate.
Keywords
computer network security; peer-to-peer computing; telecommunication traffic; P2P botnet traffic; peer-to-peer botnets; statistical traffic fingerprints; stealthy P2P botnet detection; Clustering algorithms; Electronic mail; IP networks; Monitoring; Peer to peer computing; Protocols; Storms; Botnet; Intrusion Detection; P2P; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems & Networks (DSN), 2011 IEEE/IFIP 41st International Conference on
Conference_Location
Hong Kong
ISSN
1530-0889
Print_ISBN
978-1-4244-9232-9
Electronic_ISBN
1530-0889
Type
conf
DOI
10.1109/DSN.2011.5958212
Filename
5958212
Link To Document