• DocumentCode
    1787211
  • Title

    BotCatch: Botnet detection based on coordinated group activities of compromised hosts

  • Author

    Yahyazadeh, Mosa ; Abadi, Mahdi

  • Author_Institution
    Fac. of Electr. & Comput. Eng., Tarbiat Modares Univ., Tehran, Iran
  • fYear
    2014
  • fDate
    9-11 Sept. 2014
  • Firstpage
    941
  • Lastpage
    945
  • Abstract
    Botnets have become one of the major tools used by attackers to perform various malicious activities on the Internet, such as launching distributed denial of service attacks, sending spam, leaking personal information, and so on. In this paper, we present BotCatch, a behavior-based botnet detection system that considers multiple coordinated group activities in the monitored network to identify bot-infected hosts. To achieve this goal, it first identifies suspicious hosts participating in coordinated group activities by an online incremental clustering algorithm and then calculates a negative score for each of the hosts based on several fuzzy membership functions. It then makes an informed decision and identifies a host as bot-infected if its negative score is higher than a threshold. We demonstrate the effectiveness of BotCatch to detect various botnets including HTTP-, IRC-, and P2P-based botnets using a testbed network consisting of some bot-infected hosts. The experimental results show that BotCatch can successfully detect various botnets with a high detection rate while keeping false alarm rate significantly low.
  • Keywords
    Internet; telecommunication security; BotCatch; Botnet detection; HTTP-based botnets; IRC-based botnets; Internet; P2P-based botnets; behavior-based botnet detection system; compromised hosts; coordinated group activities; false alarm rate; fuzzy membership functions; online incremental clustering algorithm; Clustering algorithms; Feature extraction; History; Malware; Monitoring; Protocols; Vectors; botnet detection; botnet lifecycle; coordinated group activity; fuzzy membership function; online incremental clustering;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Telecommunications (IST), 2014 7th International Symposium on
  • Conference_Location
    Tehran
  • Print_ISBN
    978-1-4799-5358-5
  • Type

    conf

  • DOI
    10.1109/ISTEL.2014.7000838
  • Filename
    7000838