Title :
Centralized Botnet Detection by Traffic Aggregation
Author :
Wang, Tao ; Yu, Shun-zheng
Author_Institution :
Dept. of Electron. & Commun. Eng., SUN YAT-SEN Univ., Guangzhou, China
Abstract :
Botnets with the centralized architecture provide a simple, low-latency, anonymous and efficient real-time communication platform for the botnet controllers. To our knowledge, most of the latest detected large-scale botnets are based on the centralized structure with HTTP or customized protocols. Therefore, centralized botnets detection helps greatly improve control of unwanted traffic. The main contribution of this study is the development of a common detection mechanism aiming at the centralized botnets. In this work we investigate the intrinsic characteristics based on the distributed yet bursting property of the centralized botnets. Our study shows that there exist great similarity and synchronization among the behaviors and the command and control (C&C) traffic of the bots, because the bots are controlled to operate according to the programmed schedule. Firstly we can determine if the groups of flows are suspectable by performing evaluation on the payload similarity and sequence correlation. Further, we will monitor and keep tracking with the collective and simultaneous behaviors of the suspicious groups of hosts. As is shown by conducting experiments, the proposed method can detect and hold back the centralized botnets effectively before they seriously influence the normal operation on the wide-scale network.
Keywords :
computer networks; synchronisation; telecommunication control; telecommunication network topology; telecommunication traffic; transport protocols; HTTP; botnet controllers; centralized Botnet detection; command-and-control traffic; customized protocols; payload similarity; real-time communication platform; sequence correlation; synchronization; traffic aggregation; unwanted traffic control; Centralized control; Command and control systems; Communication system traffic control; Distributed processing; Internet; Large-scale systems; Peer to peer computing; Performance evaluation; Protocols; Sun; Bot; Centralized Botnet; Command and Control(C&C); Similarity and Synchronization;
Conference_Titel :
Parallel and Distributed Processing with Applications, 2009 IEEE International Symposium on
Conference_Location :
Chengdu
Print_ISBN :
978-0-7695-3747-4
DOI :
10.1109/ISPA.2009.74