DocumentCode :
3224900
Title :
Preliminary study of host and network-based analysis on P2P Botnet detection
Author :
Abdullah, Raihana Syahirah ; Abdollah, Mohd Faizal ; Noh, Zul Azri Muhamad ; Mas´ud, Mohd Zaki ; Sahib, Shahrin ; Yusof, Rubiyah
Author_Institution :
Fac. of Inf. & Commun. Technol., Univ. Teknikal Malaysia Melaka, Durian Tunggal, Malaysia
fYear :
2013
fDate :
23-26 June 2013
Firstpage :
105
Lastpage :
109
Abstract :
Botnet is a network of compromised computer that running malicious software remotely controlled by an attacker known as Botmaster. The threat of Botnet threaten is widely dangerous and it is crucially to overcome this crisis. Some new bots use P2P protocols to construct command and control system are known as peer-to-peer (P2P) Botnet. More severe when P2P Botnet incorporated the centralized and distributed communication which make it more robust and complicated for detection. Hence, the analysis is necessary to be conducted especially in the combination of host-based and network-based in order to detect bots accurately. This paper provides the details analysis on host-based analysis and network-based analysis to detect P2P bots that will reveal their unique characteristic and behaviors. The result of experimental testbed on datasets show that it is possible to detect effectively P2P Botnet in standalone host and network packet´s payload. Thus, this analysis can be used for early warning of P2P Botnet activities in the host-and network-level as prevention mechanism.
Keywords :
computer network security; peer-to-peer computing; protocols; Botmaster; Botnet threaten; P2P botnet detection; P2P protocols; and control system; distributed communication; host based analysis; host packet payload; malicious software; network based analysis; network packet payload; peer-to-peer Botnet; Computers; Correlation; Filtering; Monitoring; Ports (Computers); Security; Switches; Botnet; Host-based; IDS; Network-based; P2P Botnet;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Technology, Informatics, Management, Engineering, and Environment (TIME-E), 2013 International Conference on
Conference_Location :
Bandung
Print_ISBN :
978-1-4673-5730-2
Type :
conf
DOI :
10.1109/TIME-E.2013.6611973
Filename :
6611973
Link To Document :
بازگشت