BotDet: A System for Real Time Botnet Command and Control Traffic Detection

被引:30
|
作者
Ghafir, Ibrahim [1 ,2 ]
Prenosil, Vaclav [1 ]
Hammoudeh, Mohammad [3 ]
Baker, Thar [4 ]
Jabbar, Sohail [5 ]
Khalid, Shehzad [6 ]
Jaf, Sardar [2 ]
机构
[1] Masaryk Univ, Fac Informat, Brno 60200, Czech Republic
[2] Univ Durham, Dept Comp Sci, Durham DH1 3LE, England
[3] Manchester Metropolitan Univ, Fac Sci & Engn, Manchester M1 5GD, Lancs, England
[4] Liverpool John Moores Univ, Dept Comp Sci, Liverpool L3 5UA, Merseyside, England
[5] Natl Text Univ, Dept Comp Sci, Faisalabad 37610, Pakistan
[6] Bahria Univ, Dept Comp Engn, Islamabad 44220, Pakistan
来源
IEEE ACCESS | 2018年 / 6卷
关键词
Critical infrastructure security; healthcare cyber attacks; malware; botnet; command and control server; intrusion detection system; alert correlation; CLOUD;
D O I
10.1109/ACCESS.2018.2846740
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the past decade, the digitization of services transformed the healthcare sector leading to a sharp rise in cybersecurity threats. Poor cybersecurity in the healthcare sector, coupled with high value of patient records attracted the attention of hackers. Sophisticated advanced persistent threats and malware have significantly contributed to increasing risks to the health sector. Many recent attacks are attributed to the spread of malicious software, e.g., ransomware or bot malware. Machines infected with bot malware can be used as tools for remote attack or even cryptomining. This paper presents a novel approach, called BotDet, for botnet Command and Control (C&C) traffic detection to defend against malware attacks in critical ultrastructure systems. There are two stages in the development of the proposed system: 1) we have developed four detection modules to detect different possible techniques used in botnet C&C communications and 2) we have designed a correlation framework to reduce the rate of false alarms raised by individual detection modules. Evaluation results show that BotDet balances the true positive rate and the false positive rate with 82.3% and 13.6%, respectively. Furthermore, it proves BotDet capability of real time detection.
引用
收藏
页码:38947 / 38958
页数:12
相关论文
共 50 条
  • [21] An advanced method for detection of botnet traffic using Intrusion Detection System
    Koli, Manoj S.
    Chavan, Manik K.
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICICCT), 2017, : 481 - 485
  • [22] Multi Attribute Real Time Traffic Inference Algorithm for Botnet Detection in Mobile Ad Hoc Network
    Kavitha, G.
    WIRELESS PERSONAL COMMUNICATIONS, 2018, 102 (04) : 3465 - 3476
  • [23] A hierarchical hybrid structure for botnet control and command
    Beijing University of Posts and Telecommunications, Beijing 100876, China
    不详
    不详
    Proc. - IEEE Int. Conf. Comput. Sci. Autom. Eng., CSAE, (483-489):
  • [24] Design of a Hybrid Command and Control Mobile Botnet
    Pieterse, Heloise
    Olivier, Martin
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY (ICIW-2013), 2013, : 183 - 192
  • [25] Evaluating Bluetooth as a Medium for Botnet Command and Control
    Singh, Kapil
    Sangal, Samrit
    Jain, Nehil
    Traynor, Patrick
    Lee, Wenke
    DETECTION OF INTRUSIONS AND MALWARE, AND VULNERABILITY ASSESSMENT, 2010, 6201 : 61 - 80
  • [26] A Resilient Real-Time Traffic Control System
    Serageldin, Ahmed
    Krings, Axel
    2015 IEEE 18TH INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS, 2015, : 2869 - 2876
  • [27] Traffic command control decision support system
    Xitong Gongcheng Lilun yu Shijian/System Engineering Theory and Practice, 2001, 21 (01):
  • [28] Experimental Validation of a Command and Control Traffic Detection Model
    Vugrin, Eric D.
    Hanson, Seth
    Cruz, Jerry
    Glatter, Casey
    Tarman, Thomas
    Pinar, Ali
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (03) : 1084 - 1097
  • [29] Real-Time Traffic Light Control System Based on Background Updating and Edge Detection
    Al Okaishi, Wahban
    Atouf, Issam
    Benrabh, Mohamed
    2019 INTERNATIONAL CONFERENCE ON WIRELESS TECHNOLOGIES, EMBEDDED AND INTELLIGENT SYSTEMS (WITS), 2019,
  • [30] Morphological Change Detection System for Real Time Traffic Analysis
    Anuradha, S. G.
    Karibasappa, K.
    Reddy, B. Eswar
    2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTER GRAPHICS, VISION AND INFORMATION SECURITY (CGVIS), 2015, : 237 - 242