GADFly: A Fast and Robust Algorithm to Detect P2P Botnets in Communication Graphs

被引:0
|
作者
Joshi, Harshvardhan P. [1 ]
Dutta, Rudra [1 ]
机构
[1] North Carolina State Univ, Dept Comp Sci, Raleigh, NC 27695 USA
关键词
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Botnets can be used to launch large scale and expensive attacks. Botnets are also difficult to detect and disable, especially when they use peer-to-peer (P2P) command & control structures. In this paper we propose GADFly - a fast and robust algorithm to detect P2P botnet structures in communication graphs built from network flow meta-data. While other algorithms have been proposed in literature that use graph analysis or machine learning techniques to detect botnets, they are either slow or have impractical false positives for realistically large graphs with millions of nodes. They also assume availability of universal communication graph data, which is not realistic. The method proposed here is able to precisely detect P2P botnet structures with extremely low false positive rates. In addition, GADFly is also very fast and robust in the face of gaps in communication graph data, making it suitable for practical deployments.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] A distributed algorithm for robust data sharing and updates in P2P database networks
    Franconi, E
    Kuper, G
    Lopatenko, A
    Zaihrayeu, I
    CURRENT TRENDS IN DATABASE TECHNOLOGY - EDBT 2004 WORKSHOPS, PROCEEDINGS, 2004, 3268 : 446 - 455
  • [42] Community Formation and Search in P2P: A Robust and Self-Adjusting Algorithm
    Das, Tathagata
    Nandi, Subrata
    Ganguly, Niloy
    2009 FIRST INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORKS (COMSNETS 2009), 2009, : 1 - 8
  • [43] A fast algorithm for construction of minimum delay multicast trees in P2P networks
    Ronasi, K.
    Firooz, M. H.
    Pakravan, M. R.
    Avanaki, A. N.
    2006 INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES,VOLS 1-3, 2006, : 1005 - +
  • [44] Design, Implementation and Evaluation of a Structured P2P Algorithm for Vehicular Communication Systems
    Prinz, Vivian
    Bader, Roland
    Woerndl, Wolfgang
    2010 IEEE 6TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2010, : 644 - 652
  • [45] Local P2P group (LPG) communication in structured mobile P2P networks
    Singh, Mahendra
    Kumar, Chiranjeev
    Nath, Prem
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 11 (07) : 3005 - 3019
  • [46] Local P2P group (LPG) communication in structured mobile P2P networks
    Mahendra Singh
    Chiranjeev Kumar
    Prem Nath
    Journal of Ambient Intelligence and Humanized Computing, 2020, 11 : 3005 - 3019
  • [47] A Geography-Based P2P Overlay Network for Fast and Robust Blockchain Systems
    Qiu, Haoran
    Ji, Tao
    Zhao, Shixiong
    Chen, Xusheng
    Qi, Ji
    Cui, Heming
    Wang, Sen
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (03) : 1572 - 1588
  • [48] Detecting P2P botnets by discovering flow dependency in C&C traffic
    Jiang, Hongling
    Shao, Xiuli
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2014, 7 (04) : 320 - 331
  • [49] Automated Simulation P2P Botnets Signature Detection by Rule-based Approach
    Abdullah, Raihana Syahirah
    Faizal, M. A.
    Noh, Zul Azri Muhamad
    Ahmad, Nurulhuda
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (08) : 131 - 135
  • [50] On Replication Algorithm in P2P VoD
    Zhou, Yipeng
    Fu, Tom Z. J.
    Chiu, Dah Ming
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2013, 21 (01) : 233 - 243