DocumentCode :
3100398
Title :
Active Botnet Probing to Identify Obscure Command and Control Channels
Author :
Gu, Guofei ; Yegneswaran, Vinod ; Porras, Phillip ; Stoll, Jennifer ; Lee, Wenke
Author_Institution :
Texas A&M Univ., College Station, TX, USA
fYear :
2009
fDate :
7-11 Dec. 2009
Firstpage :
241
Lastpage :
253
Abstract :
We consider the problem of identifying obscure chat-like botnet command and control (C & C) communications, which are indistinguishable from human-human communication using traditional signature-based techniques. Existing passive-behavior-based anomaly detection techniques are limited because they either require monitoring multiple bot-infected machines that belong to the same botnet or require extended monitoring times. In this paper, we explore the potential use of active botnet probing techniques in a network middle-box as a means to augment and complement existing passive botnet C & C detection strategies, especially for small botnets with obfuscated C & C content and infrequent C & C interactions. We present an algorithmic framework that uses hypothesis testing to separate botnet C & C dialogs from human-human conversations with desired accuracy and implement a prototype system called BotProbe. Experimental results on multiple real-world IRC bots demonstrate that our proposed active methods can successfully identify obscure and obfuscated botnet communications. A real-world user study on about one hundred participants also shows that the technique has a low false positive rate on human-human conversations. We discuss the limitations of BotProbe and hope this preliminary feasibility study on the use of active techniques in botnet research can inspire new thoughts and directions within the malware research community.
Keywords :
invasive software; BotProbe; active botnet probing; human-human communication; malware; obscure chat-like botnet command-and-control; signature-based technique; Application software; Command and control systems; Communication channels; Computer security; Condition monitoring; Engines; Internet; Protocols; Storms; Web server; Active Probing; Botnet; Botnet Detection; Command and Control (C & C); Intrusion Detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 2009. ACSAC '09. Annual
Conference_Location :
Honolulu, HI
ISSN :
1063-9527
Print_ISBN :
978-0-7695-3919-5
Type :
conf
DOI :
10.1109/ACSAC.2009.30
Filename :
5380679
Link To Document :
بازگشت