DocumentCode
612031
Title
SoK: P2PWNED - Modeling and Evaluating the Resilience of Peer-to-Peer Botnets
Author
Rossow, C. ; Andriesse, D. ; Werner, T. ; Stone-Gross, B. ; Plohmann, D. ; Dietrich, C.J. ; Bos, Herbert
Author_Institution
Inst. for Internet Security, Gelsenkirchen, Germany
fYear
2013
fDate
19-22 May 2013
Firstpage
97
Lastpage
111
Abstract
Centralized botnets are easy targets for takedown efforts by computer security researchers and law enforcement. Thus, botnet controllers have sought new ways to harden the infrastructures of their botnets. In order to meet this objective, some botnet operators have (re)designed their botnets to use Peer-to-Peer (P2P) infrastructures. Many P2P botnets are far more resilient to takedown attempts than centralized botnets, because they have no single points of failure. However, P2P botnets are subject to unique classes of attacks, such as node enumeration and poisoning. In this paper, we introduce a formal graph model to capture the intrinsic properties and fundamental vulnerabilities of P2P botnets. We apply our model to current P2P botnets to assess their resilience against attacks. We provide assessments on the sizes of all eleven active P2P botnets, showing that some P2P botnet families contain over a million bots. In addition, we have prototyped several mitigation strategies to measure the resilience of existing P2P botnets. We believe that the results from our analysis can be used to assist security researchers in evaluating mitigation strategies against current and future P2P botnets.
Keywords
computer network security; peer-to-peer computing; P2PWNED; SoK; active P2P botnets; botnet operators; centralized botnets; computer security researchers; formal graph model; intrinsic properties; law enforcement; mitigation strategies; node enumeration; node poisoning; peer-to-peer infrastructures; Malware; Peer-to-peer computing; Protocols; Resilience; Servers; Storms; Topology;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Privacy (SP), 2013 IEEE Symposium on
Conference_Location
Berkeley, CA
ISSN
1081-6011
Print_ISBN
978-1-4673-6166-8
Electronic_ISBN
1081-6011
Type
conf
DOI
10.1109/SP.2013.17
Filename
6547104
Link To Document