Novel Method for Detecting Centralized Botnets

王涛,余顺争
2010-01-01
Abstract:Botnet is a novel attack strategy evolved from traditional malware forms and imposes a serious threat on the network security.Especially,most of the existing botnets employ the centralized architecture which provides a simple,low-latency,anonymous and efficient real-time communication platform.The bots connect to a remote central server and wait for the commands from the botnet controller.The flows caused by the commands and the responses from the bots are generally very similar with each other and synchronous in time,because of the limited set of the commands and the programmed responses of the bots.The main contribution of this study is the development of a common detection mechanism aiming at the centralized botnets by monitoring the global correlated behaviors embedded in the command and control(CC) traffic.By conducting an experiment with real traffic data,it shows that this method is efficient in detecting the prevalent centralized botnets.
What problem does this paper attempt to address?