Detecting botnet by anomalous traffic

التفاصيل البيبلوغرافية
العنوان: Detecting botnet by anomalous traffic
المؤلفون: Hsiao-Chung Lin, Chia-Mei Chen
المصدر: Journal of Information Security and Applications. 21:42-51
بيانات النشر: Elsevier BV, 2015.
سنة النشر: 2015
مصطلحات موضوعية: Software_OPERATINGSYSTEMS, Computer Networks and Communications, business.industry, Computer science, ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS, Botnet, Cutwail botnet, Intrusion detection system, Computer security, computer.software_genre, Rustock botnet, Internet Relay Chat, ComputingMilieux_MANAGEMENTOFCOMPUTINGANDINFORMATIONSYSTEMS, Srizbi botnet, The Internet, Safety, Risk, Reliability and Quality, business, computer, Asprox botnet, Software
الوصف: Botnets can cause significant security threat and huge loss to organizations, and are difficult to discover their existence. Therefore they have become one of the most severe threats on the Internet. The core component of botnets is their command and control channel. Botnets often use IRC (Internet Relay Chat) as a communication channel through which the botmaster can control the bots to launch attacks or propagate more infections. In this paper, anomaly score based botnet detection is proposed to identify the botnet activities by using the similarity measurement and the periodic characteristics of botnets. To improve the detection rate, the proposed system employs two-level correlation relating the set of hosts with same anomaly behaviors. The proposed method can differentiate the malicious network traffic generated by infected hosts (bots) from that by normal IRC clients, even in a network with only a very small number of bots. The experiment results show that, regardless the size of the botnet in a network, the proposed approach efficiently detects abnormal IRC traffic and identifies botnet activities.
تدمد: 2214-2126
DOI: 10.1016/j.jisa.2014.05.002
URL الوصول: https://explore.openaire.eu/search/publication?articleId=doi_________::f223503e8446cc349e17089b6034cb7c
https://doi.org/10.1016/j.jisa.2014.05.002
Rights: CLOSED
رقم الانضمام: edsair.doi...........f223503e8446cc349e17089b6034cb7c
قاعدة البيانات: OpenAIRE
الوصف
تدمد:22142126
DOI:10.1016/j.jisa.2014.05.002