On the detection and identification of botnets

被引:12
|
作者
Seewald, Alexander K. [1 ]
Gansterer, Wilfried N. [2 ]
机构
[1] Seewald Solut, Vienna, Austria
[2] Univ Vienna, Res Lab Computat Technol & Applicat, Vienna, Austria
关键词
Botnet; E-mail spam; Traffic analysis; Machine learning; IT security;
D O I
10.1016/j.cose.2009.07.007
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We develop and discuss automated and self-adaptive systems for detecting and classifying botnets based on machine learning techniques and integration of human expertise. The proposed concept is purely passive and is based on analyzing information collected at three levels: (i) the payload of single packets received, (ii) observed access patterns to a darknet at the level of network traffic, and (iii) observed contents of TCP/IP traffic at the protocol level. We illustrate experiments based on real-life data collected with a darknet set up for this purpose to show the potential of the proposed concept for Levels (i) and (ii). As darknets cannot capture TCP/IP traffic data, we use a small spamtrap in our experiments at Level (iii). Strictly speaking, this approach for Level (iii) is not purely passive. However, traffic moving through a network could potentially be analyzed in a similar way to also obtain a purely passive system at this level. (C) 2009 Elsevier Ltd. All rights reserved.
引用
收藏
页码:45 / 58
页数:14
相关论文
共 50 条
  • [31] Structural analysis and detection of android botnets using machine learning techniques
    Kirubavathi, G.
    Anitha, R.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2018, 17 (02) : 153 - 167
  • [32] DGA-based botnets detection using DNS traffic mining
    Manasrah, Ahmed M.
    Khdour, Thair
    Freehat, Raeda
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (05) : 2045 - 2061
  • [33] Resource monitoring for the detection of parasite P2P botnets
    Rodriguez-Gomez, Rafael A.
    Macia-Fernandez, Gabriel
    Garcia-Teodoro, Pedro
    Steiner, Moritz
    Balzarotti, Davide
    COMPUTER NETWORKS, 2014, 70 : 302 - 311
  • [34] Internet of Things botnets: A survey on Artificial Intelligence based detection techniques
    Lefoane, Moemedi
    Ghafir, Ibrahim
    Kabir, Sohag
    Awan, Irfan-Ullah
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2025, 236
  • [35] Intelligent Detection of IoT Botnets Using Machine Learning and Deep Learning
    Kim, Jiyeon
    Shim, Minsun
    Hong, Seungah
    Shin, Yulim
    Choi, Eunjung
    APPLIED SCIENCES-BASEL, 2020, 10 (19): : 1 - 22
  • [36] DNS-based Anti-evasion Technique for Botnets Detection
    Lysenko, Sergii
    Pomorova, Oksana
    Savenko, Oleg
    Kryshchuk, Andrii
    Bobrovnikova, Kira
    2015 IEEE 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS (IDAACS), VOLS 1-2, 2015, : 453 - 458
  • [37] BotRevealer: Behavioral Detection of Botnets based on Botnet Life-cycle
    Khoshhalpour, Ehsan
    Shahriari, Hamid Reza
    ISECURE-ISC INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2018, 10 (01): : 55 - 61
  • [38] Structural analysis and detection of android botnets using machine learning techniques
    G. Kirubavathi
    R. Anitha
    International Journal of Information Security, 2018, 17 : 153 - 167
  • [39] Detection and Blockchain-Based Collaborative Mitigation of Internet of Things Botnets
    Sajjad, Syed Muhammad
    Mufti, Muhammad Rafiq
    Yousaf, Muhammad
    Aslam, Waqar
    Alshahrani, Reem
    Nemri, Nadhem
    Afzal, Humaira
    Khan, Muhammad Asghar
    Chen, Chien-Ming
    Wireless Communications and Mobile Computing, 2022, 2022
  • [40] Botnets: A survey
    Silva, Sergio S. C.
    Silva, Rodrigo M. P.
    Pinto, Raquel C. G.
    Salles, Ronaldo M.
    COMPUTER NETWORKS, 2013, 57 (02) : 378 - 403