Title :
Detection of Bot Infected PCs Using Destination-Based IP and Domain Whitelists During a Non-Operating Term
Author :
Takemori, Keisuke ; Nishigaki, Masakatsu ; Takami, Tomohiro ; Miyake, Yutaka
Author_Institution :
KDDI R&D Labs. Inc., Fujimino
Abstract :
Spam e-mails and distributed denial of service (DDoS) attacks have now become critical issues to the Internet. These attacks are considered to be sent from bot infected PCs. As a bot communicates with a malicious controller over an encrypted channel and updates its code frequently, it becomes difficult to detect infected personal computers (PCs) using pattern-based intrusion detection systems (IDSs) and antivirus systems (AVs). As sending attack and control packets from the bot process are independent of the user operation, a behavior monitor is effective to detect an anomaly communication. In this paper, we propose a bot detection technique that checks outbound packets with destination-based whitelists. If any outbound packets during the non-operating term do not match the whitelists, the PC is considered to be infected by the bot. The whitelists are a set of a destination IP address and/or domain names (DNs) that are listed by monitoring outbound packets from an un-infected PC. Because the many IPs and DNs are grouped into a few sub-networks and superior DNs, it is easier to maintain the destination-based whitelists than the pattern-based IDS/AV. We implement the proposal system as a host-based detector and evaluate false negative (FN) and false positive (FP) frequencies for detection of bot activities.
Keywords :
IP networks; Internet; computer viruses; cryptography; telecommunication security; unsolicited e-mail; DDoS; Internet; anomaly communication detection; antivirus system; behavior monitor; bot infected PC detection; destination-based IP; distributed denial of service attack; domain name; domain whitelist; encrypted channel; pattern-based intrusion detection system; spam e-mail; Communication system control; Computer crime; Control systems; Cryptography; Electronic mail; Intrusion detection; Microcomputers; Personal communication networks; Unsolicited electronic mail; Web and internet services;
Conference_Titel :
Global Telecommunications Conference, 2008. IEEE GLOBECOM 2008. IEEE
Conference_Location :
New Orleans, LO
Print_ISBN :
978-1-4244-2324-8
DOI :
10.1109/GLOCOM.2008.ECP.399