• DocumentCode
    3742523
  • Title

    Botnet tracing based on distributed denial of service activity analysis

  • Author

    Wei Ding;Wentao Ren;Zhen Xia;Li Wang

  • Author_Institution
    Key Laboratory of Computer Network, Southeast University, Nanjing, China
  • fYear
    2015
  • Firstpage
    685
  • Lastpage
    689
  • Abstract
    Most of DDoS(Distributed Denial of Service) attacks use botnets as the carrier, which has become one of the serious threat to Internet. However, botnet detection is difficult in backbone because C&C(command & control channel) is blended into the heavy background traffic. This paper proposed a method for locating botnet by DDoS activity data analysis and DPI(Deep Packet Inspection) technology. The DDoS attack traffic is sampled to locate suspicious hosts firstly, then the hosts´ packets are collected and analyzed by DPI technology with some DDoS parameters, such as victim, start time of the attack etc. for finding C&C and Servers. This detection model has been implemented, named BTS (Botnet tracking system) at a POP of CERNET. The tests showed the practicability of this model.
  • Keywords
    "Computer crime","IP networks","Servers","Information filters","Databases"
  • Publisher
    ieee
  • Conference_Titel
    Biomedical Engineering and Informatics (BMEI), 2015 8th International Conference on
  • Type

    conf

  • DOI
    10.1109/BMEI.2015.7401590
  • Filename
    7401590