Garlic: A Distributed Botnets Suppression System

Fuye Han,Zhen Chen,HongFeng Xu,Yong Liang
DOI: https://doi.org/10.1109/icdcsw.2012.30
2012-01-01
Abstract:Botnets are extremely versatile and are used in many attacks, for example, sending huge volumes of spam or launching Distributed Denial-of-Service (DDoS) attacks. With the development of network technology, suppressing botnets become more and more difficult. There are many reasons, firstly, the bot master will keep their own botnets as small as possible not only to hide themselves but also to rent the botnets in an easy way, secondly, bots can automatically change their command and control server (C&C) in order to hide and rescue themselves. Completely suppressing botnets is an extremely difficult challenge, but is not impossible. In this paper, we present an automatic and distributed botnets suppressing system called Garlic. Its structure is very similar to garlic, whose cloves are also distributed. This system can automatically collect network traffic from the botnet in a distributed mode, and then process these huge data using cloud computing technology, the Garlic system will generate and distribute rules when botnets are detected in data analysis. The most important feature of the Garlic is its close loop control characteristics, i.e., gather the feedback events resulted from the deployed rules, process and analyze in central node, and regenerate more effective rules to further suppress the new variant botnets. Finally, Garlic is evaluated and tested in the test bed to demonstrate its workability.
What problem does this paper attempt to address?