On the detection and identification of botnets

被引:12
|
作者
Seewald, Alexander K. [1 ]
Gansterer, Wilfried N. [2 ]
机构
[1] Seewald Solut, Vienna, Austria
[2] Univ Vienna, Res Lab Computat Technol & Applicat, Vienna, Austria
关键词
Botnet; E-mail spam; Traffic analysis; Machine learning; IT security;
D O I
10.1016/j.cose.2009.07.007
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We develop and discuss automated and self-adaptive systems for detecting and classifying botnets based on machine learning techniques and integration of human expertise. The proposed concept is purely passive and is based on analyzing information collected at three levels: (i) the payload of single packets received, (ii) observed access patterns to a darknet at the level of network traffic, and (iii) observed contents of TCP/IP traffic at the protocol level. We illustrate experiments based on real-life data collected with a darknet set up for this purpose to show the potential of the proposed concept for Levels (i) and (ii). As darknets cannot capture TCP/IP traffic data, we use a small spamtrap in our experiments at Level (iii). Strictly speaking, this approach for Level (iii) is not purely passive. However, traffic moving through a network could potentially be analyzed in a similar way to also obtain a purely passive system at this level. (C) 2009 Elsevier Ltd. All rights reserved.
引用
收藏
页码:45 / 58
页数:14
相关论文
共 50 条
  • [1] A Novel Approach for the Early Detection and Identification of Botnets
    Raj, S. Benson Edwin
    Shalini, R.
    MEMS, NANO AND SMART SYSTEMS, PTS 1-6, 2012, 403-408 : 4469 - 4475
  • [2] Lightweight Detection of Spamming Botnets
    Takesue, Masaru
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON EMERGING SECURITY INFORMATION, SYSTEMS AND TECHNOLOGIES (SECURWARE 2011), 2011, : 1 - 6
  • [3] Detection DNS Tunneling Botnets
    Savenko, Bohdan
    Lysenko, Sergii
    Bobrovnikova, Kira
    Savenko, Oleg
    Markowsky, George
    PROCEEDINGS OF THE THE 11TH IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS (IDAACS'2021), VOL 1, 2021, : 64 - 69
  • [4] An adaptive framework for the detection of novel botnets
    Cid-Fuentes, Javier Alvarez
    Szabo, Claudia
    Falkner, Katrina
    COMPUTERS & SECURITY, 2018, 79 : 148 - 161
  • [5] Analysis of Network Intrusion Detection and Potential Botnets Identification Using Selected Machine Learning Techniques
    Zabawa, Patryk
    Kedziora, Michal
    ADVANCES IN COMPUTATIONAL COLLECTIVE INTELLIGENCE, ICCCI 2024, PT II, 2024, 2166 : 43 - 53
  • [6] Botnets: A Heuristic-Based Detection Framework
    Mendonca, Luis
    Santos, Henrique
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS, 2012, : 33 - 40
  • [7] Ensemble Learning Techniques for the Detection of IoT Botnets
    Nazir, Ahsan
    He, Jingsha
    Zhu, Nafei
    Ma, Xiangjun
    Ullah, Faheem
    Qureshi, Siraj Uddin
    Wajahat, Ahsan
    PROCEEDINGS OF 2024 3RD INTERNATIONAL CONFERENCE ON CYBER SECURITY, ARTIFICIAL INTELLIGENCE AND DIGITAL ECONOMY, CSAIDE 2024, 2024, : 80 - 85
  • [8] Detection and prevention of botnets and malware in an enterprise network
    Thakur, Manoj Rameshchandra
    Khilnani, Divye Raj
    Gupta, Kushagra
    Jain, Sandeep
    Agarwal, Vineet
    Sane, Suneeta
    Sanyal, Sugata
    Dhekne, Prabhakar S.
    International Journal of Wireless and Mobile Computing, 2012, 5 (02) : 144 - 153
  • [9] Bots and Botnets: An Overview of Characteristics, Detection and Challenges
    Eslahi, Meisam
    Salleh, Rosli
    Anuar, Badrul
    2012 IEEE INTERNATIONAL CONFERENCE ON CONTROL SYSTEM, COMPUTING AND ENGINEERING (ICCSCE 2012), 2012, : 349 - 354
  • [10] Botnets Detection Based on IRC-Community
    Lu, Wei
    Ghorbani, Ali A.
    GLOBECOM 2008 - 2008 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2008,