A Taxonomy of Botnet Behavior, Detection, and Defense

被引:113
|
作者
Khattak, Sheharbano [1 ]
Ramay, Naurin Rasheed [2 ]
Khan, Kamran Riaz [2 ]
Syed, Affan A. [2 ]
Khayam, Syed Ali [3 ]
机构
[1] Univ Cambridge, Comp Lab, Cambridge CB3 0FD, England
[2] Natl Univ Comp & Emerging Sci, SysNet, Islamabad, Pakistan
[3] PLUMgrid Inc, Sunnyvale, CA 94085 USA
来源
关键词
bot; botnet; botmaster; C&C; DNS flux; IP flux; spambot; stepping-stone; cyberwarfare; DDoS; spam; cyberfraud; fast flux service network; bot family; complex event processing;
D O I
10.1109/SURV.2013.091213.00134
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A number of detection and defense mechanisms have emerged in the last decade to tackle the botnet phenomenon. It is important to organize this knowledge to better understand the botnet problem and its solution space. In this paper, we structure existing botnet literature into three comprehensive taxonomies of botnet behavioral features, detection and defenses. This elevated view highlights opportunities for network defense by revealing shortcomings in existing approaches. We introduce the notion of a dimension to denote different criteria which can be used to classify botnet detection techniques. We demonstrate that classification by dimensions is particularly useful for evaluating botnet detection mechanisms through various metrics of interest. We also show how botnet behavioral features from the first taxonomy affect the accuracy of the detection approaches in the second taxonomy. This information can be used to devise integrated detection strategies by combining complementary approaches. To provide real-world context, we liberally augment our discussions with relevant examples from security research and products.
引用
收藏
页码:898 / 924
页数:27
相关论文
共 50 条
  • [31] Corruption and botnet defense: a mean field game approach
    V. N. Kolokoltsov
    O. A. Malafeyev
    International Journal of Game Theory, 2018, 47 : 977 - 999
  • [32] Dynamic game model of botnet DDoS attack and defense
    Wang, Yichuan
    Ma, Jianfeng
    Zhang, Liumei
    Ji, Wenjiang
    Lu, Di
    Hei, Xinhong
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (16) : 3127 - 3140
  • [33] Corruption and botnet defense: a mean field game approach
    Kolokoltsov, V. N.
    Malafeyev, O. A.
    INTERNATIONAL JOURNAL OF GAME THEORY, 2018, 47 (03) : 977 - 999
  • [34] Survey and Taxonomy of Botnet Research through Life-Cycle
    Rodriguez-Gomez, Rafael A.
    Macia-Fernandez, Gabriel
    Garcia-Teodoro, Pedro
    ACM COMPUTING SURVEYS, 2013, 45 (04)
  • [35] Analysis of IoT Botnet Architectures and Recent Defense Proposals
    Mendes, Lucas D. P.
    Aloi, James
    Pimenta, Tales C.
    31ST INTERNATIONAL CONFERENCE ON MICROELECTRONICS (IEEE ICM 2019), 2019, : 186 - 189
  • [36] Optimal Attack Strategies in a Dynamic Botnet Defense Model
    Shang, Y.
    APPLIED MATHEMATICS & INFORMATION SCIENCES, 2012, 6 (01): : 29 - 33
  • [37] Botnet Defense System: Concept, Design, and Basic Strategy
    Yamaguchi, Shingo
    INFORMATION, 2020, 11 (11) : 1 - 15
  • [38] Botnet defense under EU data protection law
    Rataj, Piotr
    Computer Law and Security Review, 2025, 56
  • [39] A Basic Command and Control Strategy in Botnet Defense System
    Yamaguchi, Shingo
    2021 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2021,
  • [40] Discovering the Botnet Detection Techniques
    Rahim, Aneel
    bin Muhaya, Fahad T.
    SECURITY TECHNOLOGY, DISASTER RECOVERY AND BUSINESS CONTINUITY, 2010, 122 : 231 - 235