• DocumentCode
    3324398
  • Title

    A Systematic Study on Peer-to-Peer Botnets

  • Author

    Wang, Ping ; Wu, Lei ; Aslam, Baber ; Zou, Cliff C.

  • Author_Institution
    Sch. of Electr. Eng. & Comput. Sci., Univ. of Central Florida, Orlando, FL, USA
  • fYear
    2009
  • fDate
    3-6 Aug. 2009
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    "Botnet" is a network of computers that are compromised and controlled by an attacker. Botnets are one of the most serious threats to today\´s Internet. Most current botnets have centralized command and control (C&C) architecture. However, peer-to-peer (P2P) structured botnets have gradually emerged as a new advanced form of botnets. Without central C&C servers, P2P botnets are more resilient to defenses and countermeasures than traditional centralized botnets. In this paper, we systematically study P2P botnets along multiple dimensions: bot candidate selection, network construction, C&C mechanisms and communication protocols, and mitigation approaches. We carefully study two defense approaches: index poisoning and sybil attack. According to the common idea shared by them, we are able to give analytical results to evaluate their performance. We also propose possible counter techniques which might be developed by attackers against index poisoning and sybil attack defenses. In addition, we obtain one interesting finding: compared to traditional centralized botnets, by using index poisoning technique, it is easier to shut down or at least effectively mitigate P2P botnets that adopt existing P2P protocols and rely on file index to disseminate commands.
  • Keywords
    Internet; peer-to-peer computing; protocols; telecommunication security; Internet; P2P protocols; centralized command and control; communication protocols; computers network; index poisoning technique; peer-to-peer botnets; sybil attack; Command and control systems; Computer architecture; Computer networks; Counting circuits; Internet; Network servers; Peer to peer computing; Performance analysis; Protocols; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks, 2009. ICCCN 2009. Proceedings of 18th Internatonal Conference on
  • Conference_Location
    San Francisco, CA
  • ISSN
    1095-2055
  • Print_ISBN
    978-1-4244-4581-3
  • Electronic_ISBN
    1095-2055
  • Type

    conf

  • DOI
    10.1109/ICCCN.2009.5235360
  • Filename
    5235360