Title :
Discovery of Invariant Bot Behavior through Visual Network Monitoring System
Author :
Shahrestani, Alireza ; Feily, Maryam ; Ahmad, Rodina ; Ramadass, Sureswaran
Abstract :
Botnets are emerging as the most significant threat facing online ecosystems and computing assets due to their enormous volume and sheer power. It is a major challenge for cyber-security research community to combat the emerging threat of botnets. Most of useful approaches for botnet traffic detection are based on passive network traffic monitoring and analysis. Nevertheless, typical network traffic generates a huge amount of data for analysis. In addition, the poor user interfaces of the existing tools lead to the insufficient utilization of the captured data, and do not consider utilization of human intellectual capability. The proposed visual network monitoring system tackles these issues by adopting proper visualization techniques. The proposed visualization techniques enhance the visibility of network traffic related to invariant bot behaviors, and provide notification of bot existence without distracting the user with huge volumes of data. The visual illustration of typical bot behavior improves the botnet traffic detection process by engaging human perception capabilities. This approach assists security personnel with a visual security tool to mitigate botnet threats by discovering invariant botnet behaviors during the benign state of a botnet in small to medium size networks. Moreover, the user friendly interface of this system is interactive, flexible, and easy to use.
Keywords :
data visualisation; security of data; user interfaces; botnet traffic detection; cyber-security research community; invariant botnet behavior discovery; passive network traffic; user interface; visual network monitoring system; visual security tool; visualization techniques; Data visualization; Humans; Monitoring; Personnel; Security; Servers; Visualization; Bot Behavior; Botnet; Visualization;
Conference_Titel :
Emerging Security Information Systems and Technologies (SECURWARE), 2010 Fourth International Conference on
Conference_Location :
Venice
Print_ISBN :
978-1-4244-7517-9
Electronic_ISBN :
978-0-7695-4095-5
DOI :
10.1109/SECURWARE.2010.37