Botnets Detection Based on IRC-Community

被引:2
|
作者
Lu, Wei [1 ]
Ghorbani, Ali A. [1 ]
机构
[1] Univ New Brunswick, Fac Comp Sci, Network Secur Lab, Fredericton, NB E3B 5A3, Canada
关键词
D O I
10.1109/GLOCOM.2008.ECP.398
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Botnets are networks of compromised computers controlled under a common command and control (C&C) channel. Recognized as one the most serious security threats on current Internet infrastructure, botnets are often hidden in existing applications, e.g. IRC, HTTP, or Peer-to-Peer, which makes the botnet detection a challenging problem. Previous attempts for detecting botnets are to examine traffic content for IRC command on selected network links or by setting up honeypots. In this paper, we propose a new approach for detecting and characterizing botnets on a large-scale WiFi ISP network, in which we first classify the network traffic into different applications by using payload signatures and a novel clustering algorithm and then analyze the specific IRC application community based on the temporal-frequent characteristics of flows that leads the differentiation of malicious IRC channels created by bots from normal IRC traffic generated by human beings. We evaluate our approach with over 160 million flows collected over five consecutive days on a large scale network and results show the proposed approach successfully detects the botnet flows from over 160 million flows with a high detection rate and an acceptable low false alarm rate.
引用
收藏
页数:5
相关论文
共 50 条
  • [31] A Novel Approach of Botnets Detection Based on Analyzing Dynamical Network Traffic Behavior
    Nazari M.
    Dahmardeh Z.
    Aliabady S.
    SN Computer Science, 2021, 2 (4)
  • [32] AntibotV: A Multilevel Behaviour-Based Framework for Botnets Detection in Vehicular Networks
    Rahal, Rabah
    Amara Korba, Abdelaziz
    Ghoualmi-Zine, Nacira
    Challal, Yacine
    Ghamri-Doudane, Mohamed Yacine
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2022, 30 (01)
  • [33] AntibotV: A Multilevel Behaviour-Based Framework for Botnets Detection in Vehicular Networks
    Rabah Rahal
    Abdelaziz Amara Korba
    Nacira Ghoualmi-Zine
    Yacine Challal
    Mohamed Yacine Ghamri-Doudane
    Journal of Network and Systems Management, 2022, 30
  • [34] CCGA: Clustering and Capturing Group Activities for DGA-based botnets detection
    Liu, Zhicheng
    Yun, Xiaochun
    Zhang, Yongzheng
    Wang, Yipeng
    2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, : 136 - 143
  • [35] A Novel IRC Botnet Detection Method Based on Packet Size Sequence
    Ma, Xiaobo
    Guan, Xiaohong
    Tao, Jing
    Zheng, Qinghua
    Guo, Yun
    Liu, Lu
    Zhao, Shuang
    2010 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS - ICC 2010, 2010,
  • [36] Ensemble Learning Techniques for the Detection of IoT Botnets
    Nazir, Ahsan
    He, Jingsha
    Zhu, Nafei
    Ma, Xiangjun
    Ullah, Faheem
    Qureshi, Siraj Uddin
    Wajahat, Ahsan
    PROCEEDINGS OF 2024 3RD INTERNATIONAL CONFERENCE ON CYBER SECURITY, ARTIFICIAL INTELLIGENCE AND DIGITAL ECONOMY, CSAIDE 2024, 2024, : 80 - 85
  • [37] Detection and prevention of botnets and malware in an enterprise network
    Thakur, Manoj Rameshchandra
    Khilnani, Divye Raj
    Gupta, Kushagra
    Jain, Sandeep
    Agarwal, Vineet
    Sane, Suneeta
    Sanyal, Sugata
    Dhekne, Prabhakar S.
    International Journal of Wireless and Mobile Computing, 2012, 5 (02) : 144 - 153
  • [38] Bots and Botnets: An Overview of Characteristics, Detection and Challenges
    Eslahi, Meisam
    Salleh, Rosli
    Anuar, Badrul
    2012 IEEE INTERNATIONAL CONFERENCE ON CONTROL SYSTEM, COMPUTING AND ENGINEERING (ICCSCE 2012), 2012, : 349 - 354
  • [39] Detection of Mobile Botnets using Neural Networks
    Oulehla, Milan
    Oplatkova, Zuzana Kominkova
    Malanik, David
    PROCEEDINGS OF 2016 FUTURE TECHNOLOGIES CONFERENCE (FTC), 2016, : 1324 - 1326
  • [40] A Novel Approach for the Early Detection and Identification of Botnets
    Raj, S. Benson Edwin
    Shalini, R.
    MEMS, NANO AND SMART SYSTEMS, PTS 1-6, 2012, 403-408 : 4469 - 4475