• DocumentCode
    3705223
  • Title

    Disrupting stealthy botnets through strategic placement of detectors

  • Author

    Sridhar Venkatesan;Massimiliano Albanese;Sushil Jajodia

  • Author_Institution
    Center for Secure Information Systems, George Mason University, Fairfax, VA 22030, USA
  • fYear
    2015
  • Firstpage
    95
  • Lastpage
    103
  • Abstract
    In recent years, botnets have gained significant attention due to their extensive use in various kinds of criminal or otherwise unauthorized activities. Botnets have become increasingly sophisticated, and studies have shown that they can significantly reduce their footprint and increase their dwell time. Therefore, modern botnets can operate in stealth mode and evade detection for extended periods of time. In order to address this problem, we propose a proactive approach to strategically deploy detectors on selected network nodes, so as to either completely disrupt communication between bots and command and control nodes, or at least force the attacker to create more bots, therefore increasing the footprint of the botnet and the likelihood of detection. As the detector placement problem is intractable, we propose heuristics based on several centrality measures. Simulations results confirm that our approach can effectively increase complexity for the attacker.
  • Keywords
    "Detectors","Mission critical systems","Peer-to-peer computing","Communication networks","Servers","Security","Command and control systems"
  • Publisher
    ieee
  • Conference_Titel
    Communications and Network Security (CNS), 2015 IEEE Conference on
  • Type

    conf

  • DOI
    10.1109/CNS.2015.7346816
  • Filename
    7346816