Botnets Detection Based on IRC-Community

被引:2
|
作者
Lu, Wei [1 ]
Ghorbani, Ali A. [1 ]
机构
[1] Univ New Brunswick, Fac Comp Sci, Network Secur Lab, Fredericton, NB E3B 5A3, Canada
关键词
D O I
10.1109/GLOCOM.2008.ECP.398
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Botnets are networks of compromised computers controlled under a common command and control (C&C) channel. Recognized as one the most serious security threats on current Internet infrastructure, botnets are often hidden in existing applications, e.g. IRC, HTTP, or Peer-to-Peer, which makes the botnet detection a challenging problem. Previous attempts for detecting botnets are to examine traffic content for IRC command on selected network links or by setting up honeypots. In this paper, we propose a new approach for detecting and characterizing botnets on a large-scale WiFi ISP network, in which we first classify the network traffic into different applications by using payload signatures and a novel clustering algorithm and then analyze the specific IRC application community based on the temporal-frequent characteristics of flows that leads the differentiation of malicious IRC channels created by bots from normal IRC traffic generated by human beings. We evaluate our approach with over 160 million flows collected over five consecutive days on a large scale network and results show the proposed approach successfully detects the botnet flows from over 160 million flows with a high detection rate and an acceptable low false alarm rate.
引用
收藏
页数:5
相关论文
共 50 条
  • [21] Internet of Things botnets: A survey on Artificial Intelligence based detection techniques
    Lefoane, Moemedi
    Ghafir, Ibrahim
    Kabir, Sohag
    Awan, Irfan-Ullah
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2025, 236
  • [22] DGA-based botnets detection using DNS traffic mining
    Manasrah, Ahmed M.
    Khdour, Thair
    Freehat, Raeda
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (05) : 2045 - 2061
  • [23] DNS-based Anti-evasion Technique for Botnets Detection
    Lysenko, Sergii
    Pomorova, Oksana
    Savenko, Oleg
    Kryshchuk, Andrii
    Bobrovnikova, Kira
    2015 IEEE 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS (IDAACS), VOLS 1-2, 2015, : 453 - 458
  • [24] BotRevealer: Behavioral Detection of Botnets based on Botnet Life-cycle
    Khoshhalpour, Ehsan
    Shahriari, Hamid Reza
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2018, 10 (01): : 55 - 61
  • [25] Detection and Blockchain-Based Collaborative Mitigation of Internet of Things Botnets
    Sajjad, Syed Muhammad
    Mufti, Muhammad Rafiq
    Yousaf, Muhammad
    Aslam, Waqar
    Alshahrani, Reem
    Nemri, Nadhem
    Afzal, Humaira
    Khan, Muhammad Asghar
    Chen, Chien-Ming
    Wireless Communications and Mobile Computing, 2022, 2022
  • [26] Identifying DGA-based botnets using network anomaly detection
    Gavrilut, Dragos Teodor
    Popoiu, George
    Benchea, Razvan
    PROCEEDINGS OF 2016 18TH INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC), 2016, : 292 - 299
  • [27] Rapid detection technique for P2P-based botnets
    Yu, Ge
    Yu, Xiao-Cong
    Dong, Xiao-Mei
    Qin, Yu-Hai
    Dongbei Daxue Xuebao/Journal of Northeastern University, 2010, 31 (12): : 1709 - 1712
  • [28] An adaptive framework for the detection of novel botnets
    Cid-Fuentes, Javier Alvarez
    Szabo, Claudia
    Falkner, Katrina
    COMPUTERS & SECURITY, 2018, 79 : 148 - 161
  • [29] IRC Francais - A French learning community
    Hudson, JM
    PROCEEDINGS OF ICLS 2000 INTERNATIONAL CONFERENCE OF THE LEARNING SCIENCES, 2000, : 228 - 229
  • [30] UCAM: Usage, Communication and Access Monitoring Based Detection System for IoT Botnets
    Sajjad, Syed Muhammad
    Yousaf, Muhammad
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 1547 - 1550