• DocumentCode
    2908520
  • Title

    A Revised Ant Colony Optimization Scheme for Discovering Attack Paths of Botnet

  • Author

    Wang, Ping ; Lin, Hui-Tang ; Wang, Tzy Shiah

  • Author_Institution
    Dept. of MIS, Kun Shan Univ., Tainan, Taiwan
  • fYear
    2011
  • fDate
    7-9 Dec. 2011
  • Firstpage
    918
  • Lastpage
    923
  • Abstract
    IP trace back technique is an effective method to find either the attack origin or command-and-control (C&C) server on the Internet. The traditional ACO (ant colony optimization) constantly converged to a local minimum solution easily such that the global most portable of the final solution might be missed. Accordingly, the present study proposes a modified ACS (ant colony system) scheme designated as ACS-IPTBK to solve the IP trace back problem, predict both the most probable attack path and the computational resources needed in botnets. The ability of the ants to search all feasible attack paths is enhanced by means of a global heuristics. A series of ns2 simulations are performed to investigate the minimum resources required to successfully reconstruct the attack path. The convergence time for attack paths of different routing distances were investigated using a random graph generator based on Waxman´s scheme. Overall, the results confirm that the proposed method provides an effective means of reconstructing the path between the attacker and the victim based on the incomplete routing information from the related ISPs.
  • Keywords
    IP networks; Internet; ant colony optimisation; computer network security; graph theory; search problems; software agents; telecommunication network routing; IP trace back technique; ISP; Internet; Waxman scheme; attack paths discovery; botnet; command-and-control server; convergence time; global heuristics; incomplete routing information; ns2 simulations; path reconstruction; random graph generator; revised ant colony optimization scheme; routing distance; Convergence; Generators; IP networks; Network topology; Routing; Servers; Topology; Ant colony system; Attack path; Botnet; IP traceback; Waxman´s scheme;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Systems (ICPADS), 2011 IEEE 17th International Conference on
  • Conference_Location
    Tainan
  • ISSN
    1521-9097
  • Print_ISBN
    978-1-4577-1875-5
  • Type

    conf

  • DOI
    10.1109/ICPADS.2011.11
  • Filename
    6121380