DocumentCode
2415865
Title
A framework for financial botnet analysis
Author
Riccardi, Marco ; Oro, David ; Luna, Jesus ; Cremonini, Marco ; Vilanova, Marc
Author_Institution
eSecurity Res. Group, Barcelona Digital Technol. Centre, Barcelona, Spain
fYear
2010
fDate
18-20 Oct. 2010
Firstpage
1
Lastpage
7
Abstract
Financial botnets, those specifically aimed at carrying out financial fraud, represent a well-known threat for banking institutions all around the globe. Unfortunately, these malicious networks are responsible for huge economic losses or for conducting money laundering operations. Contrary to DDoS and spam malware, the stealthy nature of financial botnets requires new techniques and novel research in order to detect, analyze and even to take them down. This paper presents a work-in-progress research aimed at creating a system able to mitigate the financial botnet problem. The proposed system is based on a novel architecture that has been validated by one of the biggest savings banks in Spain. Based on previous experiences with two of the proposed architecture building blocks -the Dorothy framework and a blacklist-based IP reputation system-, we show that it is feasible to map financial botnet networks and to provide a non-deterministic score to its associated zombies. The proposed architecture also promotes intelligence information sharing with involved parties such as law enforcement authorities, ISPs and financial institutions. Our belief is that these functionalities will prove very useful to fight financial cybercrime.
Keywords
bank data processing; computer crime; computer forensics; fraud; invasive software; peer-to-peer computing; Dorothy; IP reputation system; Spain; banking institutions; economic losses; financial botnet analysis; financial fraud; financial institutions; information sharing; malicious networks; money laundering operations; savings banks; work-in-progress research; Banking; Bismuth; Color; Green products; Malware; Shape; Visualization; botnets; e-crime forensics framework; honeypots;
fLanguage
English
Publisher
ieee
Conference_Titel
eCrime Researchers Summit (eCrime), 2010
Conference_Location
Dallas, TX
ISSN
2159-1237
Print_ISBN
978-1-4244-7760-9
Type
conf
DOI
10.1109/ecrime.2010.5706697
Filename
5706697
Link To Document