DocumentCode
2604351
Title
Benchmarking IP blacklists for financial botnet detection
Author
Oro, David ; Luna, Jesus ; Felguera, Toni ; Vilanova, Marc ; Serna, Jetzabel
Author_Institution
eSecurity Res. Group, Barcelona Digital Technol. Centre, Barcelona, Spain
fYear
2010
fDate
23-25 Aug. 2010
Firstpage
62
Lastpage
67
Abstract
Every day, hundreds or even thousands of computers are infected with financial malware (i.e. Zeus) that forces them to become zombies or drones, capable of joining massive financial botnets that can be hired by well-organized cyber-criminals in order to steal online banking customers´ credentials. Despite the fact that detection and mitigation mechanisms for spam and DDoS-related botnets have been widely researched and developed, it is true that the passive nature (i.e. low network traffic, fewer connections) of financial botnets greatly hinder their countermeasures. Therefore, cyber-criminals are still obtaining high economical profits at relatively low risk with financial botnets. In this paper we propose the use of publicly available IP blacklists to detect both drones and Command & Control nodes that are part of financial botnets. To prove this hypothesis we have developed a formal framework capable of evaluating the quality of a blacklist by comparing it versus a baseline and taking into account different metrics. The contributed framework has been tested with approximately 500 million IP addresses, retrieved during a one-month period from seven different well-known blacklist providers. Our experimental results showed that these IP blacklists are able to detect both drones and C&C related with the Zeus botnet and most important, that it is possible to assign different quality scores to each blacklist based on our metrics. Finally, we introduce the basics of a high-performance IP reputation system that uses the previously obtained blacklists´ quality scores, in order to reply almost in real-time whether a certain IP is a member of a financial botnet or not. Our belief is that such a system can be easily integrated into e-banking anti-fraud systems.
Keywords
bank data processing; fraud; invasive software; anti fraud system; drone detection; electronic banking; financial botnet detection; financial malware; online banking; Banking; Bismuth; IP networks; Malware; Measurement; Random access memory; Real time systems; IP reputation; blacklists; botnets; security framework;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance and Security (IAS), 2010 Sixth International Conference on
Conference_Location
Atlanta, GA
Print_ISBN
978-1-4244-7407-3
Type
conf
DOI
10.1109/ISIAS.2010.5604040
Filename
5604040
Link To Document