Detecting botnet by anomalous traffic

被引:21
作者
Chen, Chia-Mei [1 ]
Lin, Hsiao-Chung [1 ]
机构
[1] Natl Sun Yat Sen Univ, Dept Informat Management, Kaohsiung 804, Taiwan
关键词
Botnet detection; Intrusion detection; IRC;
D O I
10.1016/j.jisa.2014.05.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnets can cause significant security threat and huge loss to organizations, and are difficult to discover their existence. Therefore they have become one of the most severe threats on the Internet. The core component of botnets is their command and control channel. Botnets often use IRC (Internet Relay Chat) as a communication channel through which the botmaster can control the bots to launch attacks or propagate more infections. In this paper, anomaly score based botnet detection is proposed to identify the botnet activities by using the similarity measurement and the periodic characteristics of botnets. To improve the detection rate, the proposed system employs two-level correlation relating the set of hosts with same anomaly behaviors. The proposed method can differentiate the malicious network traffic generated by infected hosts (bots) from that by normal IRC clients, even in a network with only a very small number of bots. The experiment results show that, regardless the size of the botnet in a network, the proposed approach efficiently detects abnormal IRC traffic and identifies botnet activities. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:42 / 51
页数:10
相关论文
共 50 条
  • [41] Security is Readily to Interpret: Quantitative Feature Analysis for Botnet Encrypted Malicious Traffic
    Chen, Long
    Wang, Qiaojuan
    Song, Yanqing
    Chen, Jianguo
    2023 IEEE 47TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC, 2023, : 753 - 758
  • [42] A Deep Learning Approach for Botnet Detection Using Raw Network Traffic Data
    Mohaddeseh Shahhosseini
    Hoda Mashayekhi
    Mohsen Rezvani
    Journal of Network and Systems Management, 2022, 30
  • [43] Detection of Botnet traffic by using Neuro-fuzzy based Intrusion Detection
    Pradeepthi, K., V
    Kannan, A.
    2018 10TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC), 2018, : 118 - 123
  • [44] Flow-based Identification of Botnet Traffic by Mining Multiple Log Files
    Masud, Mohammad M.
    Al-Khateeb, Tahseen
    Khan, Latifur
    Thuraisingham, Bhavani
    Hamlen, Kevin W.
    DFMA 2008: FIRST INTERNATIONAL CONFERENCE ON DISTRIBUTED FRAMEWORKS & APPLICATIONS, PROCEEDINGS, 2008, : 200 - 206
  • [45] CoCoSpot: Clustering and recognizing botnet command and control channels using traffic analysis
    Dietrich, Christian J.
    Rossow, Christian
    Pohlmann, Norbert
    COMPUTER NETWORKS, 2013, 57 (02) : 475 - 486
  • [46] A Survey of Botnet and Botnet Detection
    Feily, Maryam
    Shahrestani, Alireza
    Ramadass, Sureswaran
    2009 THIRD INTERNATIONAL CONFERENCE ON EMERGING SECURITY INFORMATION, SYSTEMS, AND TECHNOLOGIES, 2009, : 268 - +
  • [47] Baseline Traffic Modeling for Anomalous Traffic Detection on Network Transit Points
    Cho, Yoohee
    Kang, Koohong
    Kim, Ikkyun
    Jeong, Kitae
    MANAGEMENT ENABLING THE FUTURE INTERNET FOR CHANGING BUSINESS AND NEW COMPUTING SERVICES, PROCEEDINGS, 2009, 5787 : 385 - +
  • [48] Detecting anomalous access patterns in relational databases
    Kamra, Ashish
    Terzi, Evimaria
    Bertino, Elisa
    VLDB JOURNAL, 2008, 17 (05) : 1063 - 1077
  • [49] A fully scalable big data framework for Botnet detection based on network traffic analysis
    Mousavi, S. H.
    Khansari, M.
    Rahmani, R.
    INFORMATION SCIENCES, 2020, 512 : 629 - 640
  • [50] Traffic Feature-Based Botnet Detection Scheme Emphasizing the Importance of Long Patterns
    An, Yichen
    Haruta, Shuichiro
    Choi, Sanghun
    Sasase, Iwao
    IMAGE PROCESSING AND COMMUNICATIONS: TECHNIQUES, ALGORITHMS AND APPLICATIONS, 2020, 1062 : 181 - 188