• DocumentCode
    3662535
  • Title

    Botnet detection within cloud service provider networks using flow protocols

  • Author

    Mark Graham;Adrian Winckles;Erika Sanchez-Velazquez

  • Author_Institution
    Department of Computing and Technology, Anglia Ruskin University, Cambridge, United Kingdom
  • fYear
    2015
  • fDate
    7/1/2015 12:00:00 AM
  • Firstpage
    1614
  • Lastpage
    1619
  • Abstract
    Botnets continue to remain one of the most destructive threats to cyber security. This work aims to detect botnet traffic within an abstracted virtualised infrastructure, such as is found within cloud service providers. To achieve this an environment is created based on Xen hypervisor, using Open vSwitch to export NetFlow Version 9. This paper provides experimental evidence for how flow export can capture network traffic parameters for identifying the presence of a command and control botnet within a virtualised infrastructure. The conceptual framework described within this paper presents a non-intrusive detection element for a botnet protection system for cloud service providers. Such a system could protect the type of virtualised environments that will form the building blocks for the Internet of Things.
  • Keywords
    "Bismuth","5G mobile communication"
  • Publisher
    ieee
  • Conference_Titel
    Industrial Informatics (INDIN), 2015 IEEE 13th International Conference on
  • ISSN
    1935-4576
  • Electronic_ISBN
    2378-363X
  • Type

    conf

  • DOI
    10.1109/INDIN.2015.7281975
  • Filename
    7281975