DocumentCode :
2415865
Title :
A framework for financial botnet analysis
Author :
Riccardi, Marco ; Oro, David ; Luna, Jesus ; Cremonini, Marco ; Vilanova, Marc
Author_Institution :
eSecurity Res. Group, Barcelona Digital Technol. Centre, Barcelona, Spain
fYear :
2010
fDate :
18-20 Oct. 2010
Firstpage :
1
Lastpage :
7
Abstract :
Financial botnets, those specifically aimed at carrying out financial fraud, represent a well-known threat for banking institutions all around the globe. Unfortunately, these malicious networks are responsible for huge economic losses or for conducting money laundering operations. Contrary to DDoS and spam malware, the stealthy nature of financial botnets requires new techniques and novel research in order to detect, analyze and even to take them down. This paper presents a work-in-progress research aimed at creating a system able to mitigate the financial botnet problem. The proposed system is based on a novel architecture that has been validated by one of the biggest savings banks in Spain. Based on previous experiences with two of the proposed architecture building blocks -the Dorothy framework and a blacklist-based IP reputation system-, we show that it is feasible to map financial botnet networks and to provide a non-deterministic score to its associated zombies. The proposed architecture also promotes intelligence information sharing with involved parties such as law enforcement authorities, ISPs and financial institutions. Our belief is that these functionalities will prove very useful to fight financial cybercrime.
Keywords :
bank data processing; computer crime; computer forensics; fraud; invasive software; peer-to-peer computing; Dorothy; IP reputation system; Spain; banking institutions; economic losses; financial botnet analysis; financial fraud; financial institutions; information sharing; malicious networks; money laundering operations; savings banks; work-in-progress research; Banking; Bismuth; Color; Green products; Malware; Shape; Visualization; botnets; e-crime forensics framework; honeypots;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
eCrime Researchers Summit (eCrime), 2010
Conference_Location :
Dallas, TX
ISSN :
2159-1237
Print_ISBN :
978-1-4244-7760-9
Type :
conf
DOI :
10.1109/ecrime.2010.5706697
Filename :
5706697
Link To Document :
بازگشت