• DocumentCode
    2108948
  • Title

    Framework for Zombie Detection Using Neural Networks

  • Author

    Salvador, Paulo ; Nogueira, António ; Franca, U. ; Valadas, Rui

  • Author_Institution
    Inst. de Telecomun., Univ. of Aveiro, Aveiro
  • fYear
    2009
  • fDate
    24-28 May 2009
  • Firstpage
    14
  • Lastpage
    20
  • Abstract
    One of the most important threats to personal and corporate Internet security is the proliferation of zombie PCs operating as an organized network. Zombie detection is currently performed at the host level and/or network level, but these options have some important drawbacks: antivirus, anti-spyware and personal firewalls are ineffective in the detection of hosts that are compromised via new or target-specific malicious software, while network firewalls and intrusion detection systems were developed to protect the network from external attacks but they were not designed to detect and protect against vulnerabilities that are already present inside the local area network. This paper presents a new approach, based on neural networks, that is able to detect zombie PCs based on the historical traffic profiles presented by "licit" and "illicit" network applications. The evaluation of the proposed methodology relies on traffic traces obtained in a controlled environment and composed by licit traffic measured from normal activity of network applications and malicious traffic synthetically generated using the subseven backdoor. The results obtained show that the proposed methodology is able to achieve good identification results, being at the same time computationally efficient and easy to deploy in real network scenarios.
  • Keywords
    Internet; invasive software; local area networks; neural nets; telecommunication traffic; corporate Internet security; historical traffic profiles; illicit network application; licit network application; local area network; malicious software; neural networks; personal Internet security; subseven backdoor; zombie PC; zombie detection; Communication system traffic control; Electronic mail; IP networks; Intrusion detection; Local area networks; Neural networks; Personal communication networks; Protection; Telecommunication traffic; Unsolicited electronic mail; Zombie; botnet; illicit traffic; neural network;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Internet Monitoring and Protection, 2009. ICIMP '09. Fourth International Conference on
  • Conference_Location
    Venice/Mestre
  • Print_ISBN
    978-1-4244-3839-6
  • Electronic_ISBN
    978-0-7695-3612-5
  • Type

    conf

  • DOI
    10.1109/ICIMP.2009.10
  • Filename
    5076342