Title :
Botnet detection based on traffic monitoring
Author :
Zeidanloo, Hossein Rouhani ; Manaf, Azizah Bt ; Vahdani, Payam ; Tabatabaei, Farzaneh ; Zamani, Mazdak
Author_Institution :
Centre for Adv. Software Eng., Univ. of Technol. Malaysia, Kuala Lumpur, Malaysia
Abstract :
Botnet is most widespread and occurs commonly in today´s cyber attacks, resulting in serious threats to our network assets and organization´s properties. Botnets are collections of compromised computers (Bots) which are remotely controlled by its originator (BotMaster) under a common Commond-and-Control (C&C) infrastructure. They are used to distribute commands to the Bots for malicious activities such as distributed denial-of-service (DDoS) attacks, spam and phishing. Most of the existing Botnet detection approaches concentrate only on particular Botnet command and control (C&C) protocols (e.g., IRC,HTTP) and structures (e.g., centralized), and can become ineffective as Botnets change their structure and C&C techniques. In this paper, we proposed a new general detection framework. This proposed framework is based on finding similar communication patterns and behaviors among the group of hosts that are performing at least one malicious activity. The point that distinguishes our proposed detection framework from many other similar works is that there is no need for prior knowledge of Botnets such as Botnet signature.
Keywords :
invasive software; BotMaster; botnet detection; commond-and-control infrastructure; distributed denial-of-service attacks; phishing attack; spam attack; traffic monitoring; Command and control systems; Computer crime; Computer worms; Face detection; Information technology; Monitoring; Protocols; Robots; Software engineering; Telecommunication traffic; Botnet; P2P; bot; detection; malicious activity;
Conference_Titel :
Networking and Information Technology (ICNIT), 2010 International Conference on
Conference_Location :
Manila
Print_ISBN :
978-1-4244-7579-7
Electronic_ISBN :
978-1-4244-7578-0
DOI :
10.1109/ICNIT.2010.5508552