A Taxonomy of Botnet Behavior, Detection, and Defense

被引:113
|
作者
Khattak, Sheharbano [1 ]
Ramay, Naurin Rasheed [2 ]
Khan, Kamran Riaz [2 ]
Syed, Affan A. [2 ]
Khayam, Syed Ali [3 ]
机构
[1] Univ Cambridge, Comp Lab, Cambridge CB3 0FD, England
[2] Natl Univ Comp & Emerging Sci, SysNet, Islamabad, Pakistan
[3] PLUMgrid Inc, Sunnyvale, CA 94085 USA
来源
关键词
bot; botnet; botmaster; C&C; DNS flux; IP flux; spambot; stepping-stone; cyberwarfare; DDoS; spam; cyberfraud; fast flux service network; bot family; complex event processing;
D O I
10.1109/SURV.2013.091213.00134
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A number of detection and defense mechanisms have emerged in the last decade to tackle the botnet phenomenon. It is important to organize this knowledge to better understand the botnet problem and its solution space. In this paper, we structure existing botnet literature into three comprehensive taxonomies of botnet behavioral features, detection and defenses. This elevated view highlights opportunities for network defense by revealing shortcomings in existing approaches. We introduce the notion of a dimension to denote different criteria which can be used to classify botnet detection techniques. We demonstrate that classification by dimensions is particularly useful for evaluating botnet detection mechanisms through various metrics of interest. We also show how botnet behavioral features from the first taxonomy affect the accuracy of the detection approaches in the second taxonomy. This information can be used to devise integrated detection strategies by combining complementary approaches. To provide real-world context, we liberally augment our discussions with relevant examples from security research and products.
引用
收藏
页码:898 / 924
页数:27
相关论文
共 50 条
  • [21] Visualization of Invariant Bot Behavior for Effective Botnet Traffic Detection
    Shahrestani, Alireza
    Feily, Maryam
    Masood, Mona
    Muniandy, Balakrishnan
    2012 INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATION TECHNOLOGIES (ISTT), 2012, : 325 - 330
  • [22] Botnet Takedown Initiatives: A Taxonomy and Performance Model
    Shirazi, Reza
    TECHNOLOGY INNOVATION MANAGEMENT REVIEW, 2015, : 15 - 20
  • [23] IN DEFENSE OF TAXONOMY
    JARZEMBOWSKI, EA
    NATURE, 1990, 347 (6290) : 222 - 222
  • [24] Botnet and Botnet Detection Techniques in Cyber realm
    Kaur, Navdeep
    Singh, Maninder
    2016 INTERNATIONAL CONFERENCE ON INVENTIVE COMPUTATION TECHNOLOGIES (ICICT), VOL 3, 2015, : 694 - 699
  • [25] Markov Chain-Based Modeling of Malicious Botnet Spread for Botnet Defense Systems
    Kobayashi, Koichi
    2023 IEEE/SICE INTERNATIONAL SYMPOSIUM ON SYSTEM INTEGRATION, SII, 2023,
  • [26] A Botnet Detection Game
    Soper, Braden
    Musacchio, John
    2014 52ND ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2014, : 294 - 303
  • [27] Evading Botnet Detection
    Geiginger, Lisa-Marie
    Zseby, Tanja
    39TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2024, 2024, : 1331 - 1340
  • [28] Botnet as a Service towards National Defense and Security
    Khang, Tan Yock
    Abd Rahman, Nor Azlina
    2021 14TH INTERNATIONAL CONFERENCE ON DEVELOPMENTS IN ESYSTEMS ENGINEERING (DESE), 2021, : 86 - 91
  • [29] Botnet Defense System: Concept and Basic Strategy
    Yamaguchi, Shingo
    2020 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2020, : 37 - 41
  • [30] On Development of Immune Function for Botnet Defense System
    Okawa, Masato
    Yamaguchi, Shingo
    2024 11TH INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS-TAIWAN, ICCE-TAIWAN 2024, 2024, : 291 - 292