BotDet: A System for Real Time Botnet Command and Control Traffic Detection

被引:30
|
作者
Ghafir, Ibrahim [1 ,2 ]
Prenosil, Vaclav [1 ]
Hammoudeh, Mohammad [3 ]
Baker, Thar [4 ]
Jabbar, Sohail [5 ]
Khalid, Shehzad [6 ]
Jaf, Sardar [2 ]
机构
[1] Masaryk Univ, Fac Informat, Brno 60200, Czech Republic
[2] Univ Durham, Dept Comp Sci, Durham DH1 3LE, England
[3] Manchester Metropolitan Univ, Fac Sci & Engn, Manchester M1 5GD, Lancs, England
[4] Liverpool John Moores Univ, Dept Comp Sci, Liverpool L3 5UA, Merseyside, England
[5] Natl Text Univ, Dept Comp Sci, Faisalabad 37610, Pakistan
[6] Bahria Univ, Dept Comp Engn, Islamabad 44220, Pakistan
来源
IEEE ACCESS | 2018年 / 6卷
关键词
Critical infrastructure security; healthcare cyber attacks; malware; botnet; command and control server; intrusion detection system; alert correlation; CLOUD;
D O I
10.1109/ACCESS.2018.2846740
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the past decade, the digitization of services transformed the healthcare sector leading to a sharp rise in cybersecurity threats. Poor cybersecurity in the healthcare sector, coupled with high value of patient records attracted the attention of hackers. Sophisticated advanced persistent threats and malware have significantly contributed to increasing risks to the health sector. Many recent attacks are attributed to the spread of malicious software, e.g., ransomware or bot malware. Machines infected with bot malware can be used as tools for remote attack or even cryptomining. This paper presents a novel approach, called BotDet, for botnet Command and Control (C&C) traffic detection to defend against malware attacks in critical ultrastructure systems. There are two stages in the development of the proposed system: 1) we have developed four detection modules to detect different possible techniques used in botnet C&C communications and 2) we have designed a correlation framework to reduce the rate of false alarms raised by individual detection modules. Evaluation results show that BotDet balances the true positive rate and the false positive rate with 82.3% and 13.6%, respectively. Furthermore, it proves BotDet capability of real time detection.
引用
收藏
页码:38947 / 38958
页数:12
相关论文
共 50 条
  • [41] Operational real-time urban traffic control system
    Boillot, F
    Pierrelee, JC
    Lenoir, F
    Sellam, S
    TRANSPORTATION SYSTEMS 1997, VOLS 1-3, 1997, : 603 - 607
  • [42] Real Time Adaptive Traffic Control System A Hybrid Approach
    Faldu, Prayushi
    Doshi, Nishant
    Patel, Reema
    2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 697 - 701
  • [43] Design of a Multiagent System for Real-Time Traffic Control
    Vilarinho, Cristina
    Tavares, Jose Pedro
    Rossetti, Rosaldo J. F.
    IEEE INTELLIGENT SYSTEMS, 2016, 31 (04) : 68 - 80
  • [44] The Design of the Traffic Light Real-time Control System
    Gu, He
    Wang, Le-le
    Li, Nian-feng
    2015 INTERNATIONAL CONFERENCE ON ELECTRICAL AND ELECTRONICS: TECHNIQUES AND APPLICATIONS (EETA 2015), 2015, : 244 - 248
  • [45] Comparative Analysis and Evaluation of Botnet Command and Control Models
    Marupally, Pavan Roy
    Paruchuri, Vamsi
    2010 24TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2010, : 82 - 89
  • [46] Efficient Detect Scheme of Botnet Command and Control Communication
    Zeng, Jinquan
    Tang, Weiwen
    Liu, Caiming
    Hu, Jianbin
    Peng, Lingxi
    INFORMATION COMPUTING AND APPLICATIONS, PT 1, 2012, 307 : 576 - +
  • [47] Progress in Command and Control Server Finding Schemes of Botnet
    Guo, Xiaojun
    Cheng, Guang
    Hu, Yifei
    Dai, Mian
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 1723 - 1727
  • [48] Real-Time Detection of Vehicles for Advanced Traffic Signal Control
    Han, Chong
    Zhang, Qinyu
    ICCEE 2008: PROCEEDINGS OF THE 2008 INTERNATIONAL CONFERENCE ON COMPUTER AND ELECTRICAL ENGINEERING, 2008, : 245 - 249
  • [49] Real-Time Botnet Detection Using Nonnegative Tucker Decomposition
    Kanehara, Hideaki
    Murakami, Yuma
    Shimamura, Jumpei
    Takahashi, Takeshi
    Inoue, Daisuke
    Murata, Noboru
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1337 - 1344
  • [50] Integration of dynamic traffic assignment with real-time traffic adaptive control system
    Gartner, NH
    Stamatiadis, C
    TRAFFIC FLOW THEORY: SIMULATION MODELS, MACROSCOPIC FLOW RELATIONSHIPS, AND FLOW ESTIMATION AND PREDICTION, 1998, (1644): : 150 - 156