BotDet: A System for Real Time Botnet Command and Control Traffic Detection

被引:30
|
作者
Ghafir, Ibrahim [1 ,2 ]
Prenosil, Vaclav [1 ]
Hammoudeh, Mohammad [3 ]
Baker, Thar [4 ]
Jabbar, Sohail [5 ]
Khalid, Shehzad [6 ]
Jaf, Sardar [2 ]
机构
[1] Masaryk Univ, Fac Informat, Brno 60200, Czech Republic
[2] Univ Durham, Dept Comp Sci, Durham DH1 3LE, England
[3] Manchester Metropolitan Univ, Fac Sci & Engn, Manchester M1 5GD, Lancs, England
[4] Liverpool John Moores Univ, Dept Comp Sci, Liverpool L3 5UA, Merseyside, England
[5] Natl Text Univ, Dept Comp Sci, Faisalabad 37610, Pakistan
[6] Bahria Univ, Dept Comp Engn, Islamabad 44220, Pakistan
来源
IEEE ACCESS | 2018年 / 6卷
关键词
Critical infrastructure security; healthcare cyber attacks; malware; botnet; command and control server; intrusion detection system; alert correlation; CLOUD;
D O I
10.1109/ACCESS.2018.2846740
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the past decade, the digitization of services transformed the healthcare sector leading to a sharp rise in cybersecurity threats. Poor cybersecurity in the healthcare sector, coupled with high value of patient records attracted the attention of hackers. Sophisticated advanced persistent threats and malware have significantly contributed to increasing risks to the health sector. Many recent attacks are attributed to the spread of malicious software, e.g., ransomware or bot malware. Machines infected with bot malware can be used as tools for remote attack or even cryptomining. This paper presents a novel approach, called BotDet, for botnet Command and Control (C&C) traffic detection to defend against malware attacks in critical ultrastructure systems. There are two stages in the development of the proposed system: 1) we have developed four detection modules to detect different possible techniques used in botnet C&C communications and 2) we have designed a correlation framework to reduce the rate of false alarms raised by individual detection modules. Evaluation results show that BotDet balances the true positive rate and the false positive rate with 82.3% and 13.6%, respectively. Furthermore, it proves BotDet capability of real time detection.
引用
收藏
页码:38947 / 38958
页数:12
相关论文
共 50 条
  • [1] Detection of Botnet Command and Control Traffic by the Identification of Untrusted Destinations
    Burghouwt, Pieter
    Spruit, Marcel
    Sips, Henk
    INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2014, PT I, 2015, 152 : 174 - 182
  • [2] Real-Time Botnet Command and Control Characterization at the Host Level
    Etemad, Farhood Farid
    Vahdani, Payam
    2012 SIXTH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2012, : 1005 - 1009
  • [3] Periodic Behavior in Botnet Command and Control Channels Traffic
    AsSadhan, Basil
    Moura, Jose M. F.
    Lapsley, David
    GLOBECOM 2009 - 2009 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-8, 2009, : 2157 - 2162
  • [4] A SURVEY OF BOTNET DETECTION TECHNIQUES BY COMMAND AND CONTROL INFRASTRUCTURE
    Hyslip, Thomas S.
    Pittman, Jason M.
    JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2015, 10 (01) : 7 - 25
  • [5] A Basic Command and Control Strategy in Botnet Defense System
    Yamaguchi, Shingo
    2021 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2021,
  • [6] Botnet command and control techniques
    Heron, Simon
    Network Security, 2007, 2007 (04) : 13 - 16
  • [7] Botnet Command and Control Mechanisms
    Zeidanloo, Hossein Rouhani
    Manaf, Azizah Abdul
    SECOND INTERNATIONAL CONFERENCE ON COMPUTER AND ELECTRICAL ENGINEERING, VOL 1, PROCEEDINGS, 2009, : 564 - 568
  • [8] CoCoSpot: Clustering and recognizing botnet command and control channels using traffic analysis
    Dietrich, Christian J.
    Rossow, Christian
    Pohlmann, Norbert
    COMPUTER NETWORKS, 2013, 57 (02) : 475 - 486
  • [9] REAL TIME TRAFFIC CONGESTION DETECTION SYSTEM
    Nidhal, Ahmed
    Ngah, Umi Kalthum
    Ismail, Widad
    2014 5TH INTERNATIONAL CONFERENCE ON INTELLIGENT AND ADVANCED SYSTEMS (ICIAS 2014), 2014,
  • [10] Whispering Botnet Command and Control Instructions
    Baden, Mathis
    Torres, Christof Ferreira
    Pontiveros, Beltran Borja Fiz
    State, Radu
    2019 CRYPTO VALLEY CONFERENCE ON BLOCKCHAIN TECHNOLOGY (CVCBT 2019), 2019, : 77 - 81