Title :
Disrupting stealthy botnets through strategic placement of detectors
Author :
Sridhar Venkatesan;Massimiliano Albanese;Sushil Jajodia
Author_Institution :
Center for Secure Information Systems, George Mason University, Fairfax, VA 22030, USA
Abstract :
In recent years, botnets have gained significant attention due to their extensive use in various kinds of criminal or otherwise unauthorized activities. Botnets have become increasingly sophisticated, and studies have shown that they can significantly reduce their footprint and increase their dwell time. Therefore, modern botnets can operate in stealth mode and evade detection for extended periods of time. In order to address this problem, we propose a proactive approach to strategically deploy detectors on selected network nodes, so as to either completely disrupt communication between bots and command and control nodes, or at least force the attacker to create more bots, therefore increasing the footprint of the botnet and the likelihood of detection. As the detector placement problem is intractable, we propose heuristics based on several centrality measures. Simulations results confirm that our approach can effectively increase complexity for the attacker.
Keywords :
"Detectors","Mission critical systems","Peer-to-peer computing","Communication networks","Servers","Security","Command and control systems"
Conference_Titel :
Communications and Network Security (CNS), 2015 IEEE Conference on
DOI :
10.1109/CNS.2015.7346816