DocumentCode
2108948
Title
Framework for Zombie Detection Using Neural Networks
Author
Salvador, Paulo ; Nogueira, António ; Franca, U. ; Valadas, Rui
Author_Institution
Inst. de Telecomun., Univ. of Aveiro, Aveiro
fYear
2009
fDate
24-28 May 2009
Firstpage
14
Lastpage
20
Abstract
One of the most important threats to personal and corporate Internet security is the proliferation of zombie PCs operating as an organized network. Zombie detection is currently performed at the host level and/or network level, but these options have some important drawbacks: antivirus, anti-spyware and personal firewalls are ineffective in the detection of hosts that are compromised via new or target-specific malicious software, while network firewalls and intrusion detection systems were developed to protect the network from external attacks but they were not designed to detect and protect against vulnerabilities that are already present inside the local area network. This paper presents a new approach, based on neural networks, that is able to detect zombie PCs based on the historical traffic profiles presented by "licit" and "illicit" network applications. The evaluation of the proposed methodology relies on traffic traces obtained in a controlled environment and composed by licit traffic measured from normal activity of network applications and malicious traffic synthetically generated using the subseven backdoor. The results obtained show that the proposed methodology is able to achieve good identification results, being at the same time computationally efficient and easy to deploy in real network scenarios.
Keywords
Internet; invasive software; local area networks; neural nets; telecommunication traffic; corporate Internet security; historical traffic profiles; illicit network application; licit network application; local area network; malicious software; neural networks; personal Internet security; subseven backdoor; zombie PC; zombie detection; Communication system traffic control; Electronic mail; IP networks; Intrusion detection; Local area networks; Neural networks; Personal communication networks; Protection; Telecommunication traffic; Unsolicited electronic mail; Zombie; botnet; illicit traffic; neural network;
fLanguage
English
Publisher
ieee
Conference_Titel
Internet Monitoring and Protection, 2009. ICIMP '09. Fourth International Conference on
Conference_Location
Venice/Mestre
Print_ISBN
978-1-4244-3839-6
Electronic_ISBN
978-0-7695-3612-5
Type
conf
DOI
10.1109/ICIMP.2009.10
Filename
5076342
Link To Document