On the detection and identification of botnets

被引:12
|
作者
Seewald, Alexander K. [1 ]
Gansterer, Wilfried N. [2 ]
机构
[1] Seewald Solut, Vienna, Austria
[2] Univ Vienna, Res Lab Computat Technol & Applicat, Vienna, Austria
关键词
Botnet; E-mail spam; Traffic analysis; Machine learning; IT security;
D O I
10.1016/j.cose.2009.07.007
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We develop and discuss automated and self-adaptive systems for detecting and classifying botnets based on machine learning techniques and integration of human expertise. The proposed concept is purely passive and is based on analyzing information collected at three levels: (i) the payload of single packets received, (ii) observed access patterns to a darknet at the level of network traffic, and (iii) observed contents of TCP/IP traffic at the protocol level. We illustrate experiments based on real-life data collected with a darknet set up for this purpose to show the potential of the proposed concept for Levels (i) and (ii). As darknets cannot capture TCP/IP traffic data, we use a small spamtrap in our experiments at Level (iii). Strictly speaking, this approach for Level (iii) is not purely passive. However, traffic moving through a network could potentially be analyzed in a similar way to also obtain a purely passive system at this level. (C) 2009 Elsevier Ltd. All rights reserved.
引用
收藏
页码:45 / 58
页数:14
相关论文
共 50 条
  • [21] Collaborative agent-based detection of DDoS IoT botnets
    Giachoudis, Nikolaos
    Damiris, Georgios-Paraskevas
    Theodoridis, Georgios
    Spathoulas, Georgios
    2019 15TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING IN SENSOR SYSTEMS (DCOSS), 2019, : 205 - 211
  • [22] Hardware Isolation Technique for IRC-Based Botnets Detection
    Hategekimana, Festus
    Tbatou, Adil
    Bobda, Christophe
    Kamhoua, Charles
    Kwiat, Kevin
    2015 INTERNATIONAL CONFERENCE ON RECONFIGURABLE COMPUTING AND FPGAS (RECONFIG), 2015,
  • [23] BOTNETs: A Network Security Issue From Definition to Detection and Prevention
    Iftikhar, Umar
    Asrar, Kashif
    Waqas, Maria
    Ali, Syed Abbas
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (11) : 432 - 436
  • [24] SHIELDNET: An Adaptive Detection Mechanism against Vehicular Botnets in VANETs
    Garip, Mevlut Turker
    Lin, Jonathan
    Reiher, Peter
    Gerla, Mario
    2019 IEEE VEHICULAR NETWORKING CONFERENCE (VNC), 2019,
  • [25] Zombies and botnets
    Choo, Kim-Kwang
    TRENDS AND ISSUES IN CRIME AND CRIMINAL JUSTICE, 2007, (333): : 1 - 6
  • [26] Information Technology for Botnets Detection Based on Their Behaviour in the Corporate Area Network
    Lysenko, Sergii
    Savenko, Oleg
    Bobrovnikova, Kira
    Kryshchuk, Andrii
    Savenko, Bohdan
    COMPUTER NETWORKS (CN 2017), 2017, 718 : 166 - 181
  • [27] BotScoop: Scalable detection of DGA based botnets using DNS traffic
    Khehra, Gulbadan
    Sofat, Sanjeev
    2018 9TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2018,
  • [28] Detection of fast-flux botnets through DNS traffic analysis
    Soltanaghaei, E.
    Kharrazi, M.
    SCIENTIA IRANICA, 2015, 22 (06) : 2389 - 2400
  • [29] BOTNETS of Things
    Schneier, Bruce
    TECHNOLOGY REVIEW, 2017, 120 (02) : 89 - 91
  • [30] Of Bees and Botnets
    Sarvepalli, Vijay
    SWARM INTELLIGENCE (ANTS 2018), 2018, 11172 : 433 - 434