Detecting New P2P Botnet with Multi-chart CUSUM

Jian Kang,Jun-Yao Zhang,Qiang Li,Zhuo Li
DOI: https://doi.org/10.1109/nswctc.2009.107
2009-01-01
Abstract:Botnets have been recognized as one of the most important threats to the Internet security. They are engaged in DDOS attacks, email spamming and other malicious activities likewise. Traditional botnets usually organized themselves in a hierarchy architecture, which offers professionals opportunities to detect or defend the botnets in their servers. However, newly-appeared P2P botnet such as Storm botnet, are revealing a decentralized feature, which brought difficulties in detection and mitigation. We believe that it is the very trend of future botnet developmentā€”adopting more sophisticated methods from being detected. Thus, in this paper, we analyze the basic principles and mechanism of this decentralized P2P botnet, and present a novel detecting method using Multi-chart CUSUM.
What problem does this paper attempt to address?