DocumentCode
3705223
Title
Disrupting stealthy botnets through strategic placement of detectors
Author
Sridhar Venkatesan;Massimiliano Albanese;Sushil Jajodia
Author_Institution
Center for Secure Information Systems, George Mason University, Fairfax, VA 22030, USA
fYear
2015
Firstpage
95
Lastpage
103
Abstract
In recent years, botnets have gained significant attention due to their extensive use in various kinds of criminal or otherwise unauthorized activities. Botnets have become increasingly sophisticated, and studies have shown that they can significantly reduce their footprint and increase their dwell time. Therefore, modern botnets can operate in stealth mode and evade detection for extended periods of time. In order to address this problem, we propose a proactive approach to strategically deploy detectors on selected network nodes, so as to either completely disrupt communication between bots and command and control nodes, or at least force the attacker to create more bots, therefore increasing the footprint of the botnet and the likelihood of detection. As the detector placement problem is intractable, we propose heuristics based on several centrality measures. Simulations results confirm that our approach can effectively increase complexity for the attacker.
Keywords
"Detectors","Mission critical systems","Peer-to-peer computing","Communication networks","Servers","Security","Command and control systems"
Publisher
ieee
Conference_Titel
Communications and Network Security (CNS), 2015 IEEE Conference on
Type
conf
DOI
10.1109/CNS.2015.7346816
Filename
7346816
Link To Document