• DocumentCode
    3100398
  • Title

    Active Botnet Probing to Identify Obscure Command and Control Channels

  • Author

    Gu, Guofei ; Yegneswaran, Vinod ; Porras, Phillip ; Stoll, Jennifer ; Lee, Wenke

  • Author_Institution
    Texas A&M Univ., College Station, TX, USA
  • fYear
    2009
  • fDate
    7-11 Dec. 2009
  • Firstpage
    241
  • Lastpage
    253
  • Abstract
    We consider the problem of identifying obscure chat-like botnet command and control (C & C) communications, which are indistinguishable from human-human communication using traditional signature-based techniques. Existing passive-behavior-based anomaly detection techniques are limited because they either require monitoring multiple bot-infected machines that belong to the same botnet or require extended monitoring times. In this paper, we explore the potential use of active botnet probing techniques in a network middle-box as a means to augment and complement existing passive botnet C & C detection strategies, especially for small botnets with obfuscated C & C content and infrequent C & C interactions. We present an algorithmic framework that uses hypothesis testing to separate botnet C & C dialogs from human-human conversations with desired accuracy and implement a prototype system called BotProbe. Experimental results on multiple real-world IRC bots demonstrate that our proposed active methods can successfully identify obscure and obfuscated botnet communications. A real-world user study on about one hundred participants also shows that the technique has a low false positive rate on human-human conversations. We discuss the limitations of BotProbe and hope this preliminary feasibility study on the use of active techniques in botnet research can inspire new thoughts and directions within the malware research community.
  • Keywords
    invasive software; BotProbe; active botnet probing; human-human communication; malware; obscure chat-like botnet command-and-control; signature-based technique; Application software; Command and control systems; Communication channels; Computer security; Condition monitoring; Engines; Internet; Protocols; Storms; Web server; Active Probing; Botnet; Botnet Detection; Command and Control (C & C); Intrusion Detection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2009. ACSAC '09. Annual
  • Conference_Location
    Honolulu, HI
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3919-5
  • Type

    conf

  • DOI
    10.1109/ACSAC.2009.30
  • Filename
    5380679