• DocumentCode
    3029557
  • Title

    Centralized Botnet Detection by Traffic Aggregation

  • Author

    Wang, Tao ; Yu, Shun-zheng

  • Author_Institution
    Dept. of Electron. & Commun. Eng., SUN YAT-SEN Univ., Guangzhou, China
  • fYear
    2009
  • fDate
    10-12 Aug. 2009
  • Firstpage
    86
  • Lastpage
    93
  • Abstract
    Botnets with the centralized architecture provide a simple, low-latency, anonymous and efficient real-time communication platform for the botnet controllers. To our knowledge, most of the latest detected large-scale botnets are based on the centralized structure with HTTP or customized protocols. Therefore, centralized botnets detection helps greatly improve control of unwanted traffic. The main contribution of this study is the development of a common detection mechanism aiming at the centralized botnets. In this work we investigate the intrinsic characteristics based on the distributed yet bursting property of the centralized botnets. Our study shows that there exist great similarity and synchronization among the behaviors and the command and control (C&C) traffic of the bots, because the bots are controlled to operate according to the programmed schedule. Firstly we can determine if the groups of flows are suspectable by performing evaluation on the payload similarity and sequence correlation. Further, we will monitor and keep tracking with the collective and simultaneous behaviors of the suspicious groups of hosts. As is shown by conducting experiments, the proposed method can detect and hold back the centralized botnets effectively before they seriously influence the normal operation on the wide-scale network.
  • Keywords
    computer networks; synchronisation; telecommunication control; telecommunication network topology; telecommunication traffic; transport protocols; HTTP; botnet controllers; centralized Botnet detection; command-and-control traffic; customized protocols; payload similarity; real-time communication platform; sequence correlation; synchronization; traffic aggregation; unwanted traffic control; Centralized control; Command and control systems; Communication system traffic control; Distributed processing; Internet; Large-scale systems; Peer to peer computing; Performance evaluation; Protocols; Sun; Bot; Centralized Botnet; Command and Control(C&C); Similarity and Synchronization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel and Distributed Processing with Applications, 2009 IEEE International Symposium on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-0-7695-3747-4
  • Type

    conf

  • DOI
    10.1109/ISPA.2009.74
  • Filename
    5207950