DocumentCode :
3742523
Title :
Botnet tracing based on distributed denial of service activity analysis
Author :
Wei Ding;Wentao Ren;Zhen Xia;Li Wang
Author_Institution :
Key Laboratory of Computer Network, Southeast University, Nanjing, China
fYear :
2015
Firstpage :
685
Lastpage :
689
Abstract :
Most of DDoS(Distributed Denial of Service) attacks use botnets as the carrier, which has become one of the serious threat to Internet. However, botnet detection is difficult in backbone because C&C(command & control channel) is blended into the heavy background traffic. This paper proposed a method for locating botnet by DDoS activity data analysis and DPI(Deep Packet Inspection) technology. The DDoS attack traffic is sampled to locate suspicious hosts firstly, then the hosts´ packets are collected and analyzed by DPI technology with some DDoS parameters, such as victim, start time of the attack etc. for finding C&C and Servers. This detection model has been implemented, named BTS (Botnet tracking system) at a POP of CERNET. The tests showed the practicability of this model.
Keywords :
"Computer crime","IP networks","Servers","Information filters","Databases"
Publisher :
ieee
Conference_Titel :
Biomedical Engineering and Informatics (BMEI), 2015 8th International Conference on
Type :
conf
DOI :
10.1109/BMEI.2015.7401590
Filename :
7401590
Link To Document :
بازگشت