Title :
BotCop: An Online Botnet Traffic Classifier
Author :
Lu, Wei ; Tavallaee, Mahbod ; Rammidi, Goaletsa ; Ghorbani, Ali A.
Author_Institution :
Fac. of Comput. Sci., Univ. of New Brunswick Fredericton, Fredericton, NB
Abstract :
A botnet is a network of compromised computers infected with malicious code that can be controlled remotely under a common command and control (C&C) channel. As one the most serious security threats to the Internet, a botnet cannot only be implemented with existing network applications (e.g. IRC, HTTP, or Peer-to-Peer) but also can be constructed by unknown or creative applications, thus making the botnet detection a challenging problem. In this paper, we propose a new online botnet traffic classification system, called BotCop, in which the network traffic are fully classified into different application communities by using payload signatures and a novel decision tree model, and then on each obtained application community, the temporal-frequent characteristic of flows is studied and analyzed to differentiate the malicious communication traffic created by bots from normal traffic generated by human beings. We evaluate our approach with about 30 million flows collected over one day on a large-scale WiFi ISP network and results show that the proposed approach successfully detects an IRC botnet from about 30 million flows with a high detection rate and a low false alarm rate.
Keywords :
Internet; decision trees; telecommunication security; telecommunication traffic; BotCop; Internet; command and control channel; decision tree; false alarm rate; malicious code; malicious communication traffic; online botnet traffic classification system; online botnet traffic classifier; payload signatures; security threats; Application software; Classification tree analysis; Command and control systems; Communication system traffic control; Computer networks; IP networks; Payloads; Peer to peer computing; Telecommunication traffic; Traffic control;
Conference_Titel :
Communication Networks and Services Research Conference, 2009. CNSR '09. Seventh Annual
Conference_Location :
Moncton, NB
Print_ISBN :
978-1-4244-4155-6
Electronic_ISBN :
978-0-7695-3649-1
DOI :
10.1109/CNSR.2009.21