• DocumentCode
    3050224
  • Title

    Discovery of Invariant Bot Behavior through Visual Network Monitoring System

  • Author

    Shahrestani, Alireza ; Feily, Maryam ; Ahmad, Rodina ; Ramadass, Sureswaran

  • fYear
    2010
  • fDate
    18-25 July 2010
  • Firstpage
    182
  • Lastpage
    188
  • Abstract
    Botnets are emerging as the most significant threat facing online ecosystems and computing assets due to their enormous volume and sheer power. It is a major challenge for cyber-security research community to combat the emerging threat of botnets. Most of useful approaches for botnet traffic detection are based on passive network traffic monitoring and analysis. Nevertheless, typical network traffic generates a huge amount of data for analysis. In addition, the poor user interfaces of the existing tools lead to the insufficient utilization of the captured data, and do not consider utilization of human intellectual capability. The proposed visual network monitoring system tackles these issues by adopting proper visualization techniques. The proposed visualization techniques enhance the visibility of network traffic related to invariant bot behaviors, and provide notification of bot existence without distracting the user with huge volumes of data. The visual illustration of typical bot behavior improves the botnet traffic detection process by engaging human perception capabilities. This approach assists security personnel with a visual security tool to mitigate botnet threats by discovering invariant botnet behaviors during the benign state of a botnet in small to medium size networks. Moreover, the user friendly interface of this system is interactive, flexible, and easy to use.
  • Keywords
    data visualisation; security of data; user interfaces; botnet traffic detection; cyber-security research community; invariant botnet behavior discovery; passive network traffic; user interface; visual network monitoring system; visual security tool; visualization techniques; Data visualization; Humans; Monitoring; Personnel; Security; Servers; Visualization; Bot Behavior; Botnet; Visualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging Security Information Systems and Technologies (SECURWARE), 2010 Fourth International Conference on
  • Conference_Location
    Venice
  • Print_ISBN
    978-1-4244-7517-9
  • Electronic_ISBN
    978-0-7695-4095-5
  • Type

    conf

  • DOI
    10.1109/SECURWARE.2010.37
  • Filename
    5633664