DocumentCode :
1787211
Title :
BotCatch: Botnet detection based on coordinated group activities of compromised hosts
Author :
Yahyazadeh, Mosa ; Abadi, Mahdi
Author_Institution :
Fac. of Electr. & Comput. Eng., Tarbiat Modares Univ., Tehran, Iran
fYear :
2014
fDate :
9-11 Sept. 2014
Firstpage :
941
Lastpage :
945
Abstract :
Botnets have become one of the major tools used by attackers to perform various malicious activities on the Internet, such as launching distributed denial of service attacks, sending spam, leaking personal information, and so on. In this paper, we present BotCatch, a behavior-based botnet detection system that considers multiple coordinated group activities in the monitored network to identify bot-infected hosts. To achieve this goal, it first identifies suspicious hosts participating in coordinated group activities by an online incremental clustering algorithm and then calculates a negative score for each of the hosts based on several fuzzy membership functions. It then makes an informed decision and identifies a host as bot-infected if its negative score is higher than a threshold. We demonstrate the effectiveness of BotCatch to detect various botnets including HTTP-, IRC-, and P2P-based botnets using a testbed network consisting of some bot-infected hosts. The experimental results show that BotCatch can successfully detect various botnets with a high detection rate while keeping false alarm rate significantly low.
Keywords :
Internet; telecommunication security; BotCatch; Botnet detection; HTTP-based botnets; IRC-based botnets; Internet; P2P-based botnets; behavior-based botnet detection system; compromised hosts; coordinated group activities; false alarm rate; fuzzy membership functions; online incremental clustering algorithm; Clustering algorithms; Feature extraction; History; Malware; Monitoring; Protocols; Vectors; botnet detection; botnet lifecycle; coordinated group activity; fuzzy membership function; online incremental clustering;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Telecommunications (IST), 2014 7th International Symposium on
Conference_Location :
Tehran
Print_ISBN :
978-1-4799-5358-5
Type :
conf
DOI :
10.1109/ISTEL.2014.7000838
Filename :
7000838
Link To Document :
بازگشت