• DocumentCode
    612031
  • Title

    SoK: P2PWNED - Modeling and Evaluating the Resilience of Peer-to-Peer Botnets

  • Author

    Rossow, C. ; Andriesse, D. ; Werner, T. ; Stone-Gross, B. ; Plohmann, D. ; Dietrich, C.J. ; Bos, Herbert

  • Author_Institution
    Inst. for Internet Security, Gelsenkirchen, Germany
  • fYear
    2013
  • fDate
    19-22 May 2013
  • Firstpage
    97
  • Lastpage
    111
  • Abstract
    Centralized botnets are easy targets for takedown efforts by computer security researchers and law enforcement. Thus, botnet controllers have sought new ways to harden the infrastructures of their botnets. In order to meet this objective, some botnet operators have (re)designed their botnets to use Peer-to-Peer (P2P) infrastructures. Many P2P botnets are far more resilient to takedown attempts than centralized botnets, because they have no single points of failure. However, P2P botnets are subject to unique classes of attacks, such as node enumeration and poisoning. In this paper, we introduce a formal graph model to capture the intrinsic properties and fundamental vulnerabilities of P2P botnets. We apply our model to current P2P botnets to assess their resilience against attacks. We provide assessments on the sizes of all eleven active P2P botnets, showing that some P2P botnet families contain over a million bots. In addition, we have prototyped several mitigation strategies to measure the resilience of existing P2P botnets. We believe that the results from our analysis can be used to assist security researchers in evaluating mitigation strategies against current and future P2P botnets.
  • Keywords
    computer network security; peer-to-peer computing; P2PWNED; SoK; active P2P botnets; botnet operators; centralized botnets; computer security researchers; formal graph model; intrinsic properties; law enforcement; mitigation strategies; node enumeration; node poisoning; peer-to-peer infrastructures; Malware; Peer-to-peer computing; Protocols; Resilience; Servers; Storms; Topology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy (SP), 2013 IEEE Symposium on
  • Conference_Location
    Berkeley, CA
  • ISSN
    1081-6011
  • Print_ISBN
    978-1-4673-6166-8
  • Electronic_ISBN
    1081-6011
  • Type

    conf

  • DOI
    10.1109/SP.2013.17
  • Filename
    6547104