A Taxonomy of Botnet Behavior, Detection, and Defense

被引:113
|
作者
Khattak, Sheharbano [1 ]
Ramay, Naurin Rasheed [2 ]
Khan, Kamran Riaz [2 ]
Syed, Affan A. [2 ]
Khayam, Syed Ali [3 ]
机构
[1] Univ Cambridge, Comp Lab, Cambridge CB3 0FD, England
[2] Natl Univ Comp & Emerging Sci, SysNet, Islamabad, Pakistan
[3] PLUMgrid Inc, Sunnyvale, CA 94085 USA
来源
关键词
bot; botnet; botmaster; C&C; DNS flux; IP flux; spambot; stepping-stone; cyberwarfare; DDoS; spam; cyberfraud; fast flux service network; bot family; complex event processing;
D O I
10.1109/SURV.2013.091213.00134
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A number of detection and defense mechanisms have emerged in the last decade to tackle the botnet phenomenon. It is important to organize this knowledge to better understand the botnet problem and its solution space. In this paper, we structure existing botnet literature into three comprehensive taxonomies of botnet behavioral features, detection and defenses. This elevated view highlights opportunities for network defense by revealing shortcomings in existing approaches. We introduce the notion of a dimension to denote different criteria which can be used to classify botnet detection techniques. We demonstrate that classification by dimensions is particularly useful for evaluating botnet detection mechanisms through various metrics of interest. We also show how botnet behavioral features from the first taxonomy affect the accuracy of the detection approaches in the second taxonomy. This information can be used to devise integrated detection strategies by combining complementary approaches. To provide real-world context, we liberally augment our discussions with relevant examples from security research and products.
引用
收藏
页码:898 / 924
页数:27
相关论文
共 50 条
  • [1] A Review on Taxonomy of Botnet Detection
    Panimalar, P.
    Rameshkumar, K.
    2014 INTERNATIONAL CONFERENCE ON ADVANCES IN ENGINEERING AND TECHNOLOGY (ICAET), 2014,
  • [2] A Taxonomy of Botnet Detection Techniques
    Zeidanloo, Hossein Rouhani
    Shooshtari, Mohammad Jorjor Zadeh
    Amoli, Payam Vahdani
    Safari, M.
    Zamani, Mazdak
    ICCSIT 2010 - 3RD IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, VOL 2, 2010, : 158 - 162
  • [3] A Survey on Botnet: Classification, Detection and Defense
    Amini, Pedram
    Araghizadeh, Muhammad Amin
    Azmi, Reza
    2015 INTERNATIONAL ELECTRONICS SYMPOSIUM (IES), 2015, : 233 - 238
  • [4] A taxonomy of botnet structures
    Dagon, David
    Gu, Guofei
    Lee, Christopher P.
    Lee, Wenke
    TWENTY-THIRD ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2007, : 325 - 338
  • [5] A taxonomy of botnet structures
    Dagon, David
    Gu, Guofei
    Lee, Christopher P.
    Lee, Wenke
    BOTNET DETECTION: COUNTERING THE LARGEST SECURITY THREAT, 2008, 36 : 143 - +
  • [6] Botnet detection based on network behavior
    Strayer, W. Timothy
    Lapsely, David
    Walsh, Robert
    Livadas, Carl
    BOTNET DETECTION: COUNTERING THE LARGEST SECURITY THREAT, 2008, 36 : 1 - +
  • [7] Dynamic Reinforcement Learning for Network Defense: Botnet Detection and Eradication
    Schabinger, Robert M.
    Carlin, Caleb
    Mullin, Jonathan
    Bierbrauer, David A.
    Nack, Emily A.
    Pavlik, John A.
    Wei, Alexander V.
    Bastian, Nathaniel D.
    Ahiskali, Metin B.
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS VI, 2024, 13051
  • [8] Behavior-based botnet detection in parallel
    Wang, Kuochen
    Huang, Chun-Ying
    Tsai, Li-Yang
    Lin, Ying-Dar
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (11) : 1849 - 1859
  • [9] IRC botnet detection based on host behavior
    Wang, Wei
    Fang, Bin-Xing
    Cui, Xiang
    Jisuanji Xuebao/Chinese Journal of Computers, 2009, 32 (10): : 1980 - 1988
  • [10] A Survey of Botnet and Botnet Detection
    Feily, Maryam
    Shahrestani, Alireza
    Ramadass, Sureswaran
    2009 THIRD INTERNATIONAL CONFERENCE ON EMERGING SECURITY INFORMATION, SYSTEMS, AND TECHNOLOGIES, 2009, : 268 - +