Modeling Connections Behavior for Web-Based Bots Detection

Binbin Wang,Zhitang Li,Dong Li,Feng Liu,Hao Chen
DOI: https://doi.org/10.1109/EBISS.2010.5473532
2010-01-01
Abstract:Botnet has become a prevalent platform for malicious attacks, which poses a significant threat to Internet security. Recently, botnets are inclined to utilize HTTP to route their command and control (C&C) communication instead of using the protocol Internet Relay Chat (IRC). And these web-based C&C bots try to blend into normal HTTP traffic, which makes them more difficult to be identified. In this work, we propose an automatic approach to identify web-based C&C bots by modeling the essential network behavior of web-based bots in supervised network. Experimental results show the proposed approach is very efficient and can detect web-base bots with low false positive ratio.
What problem does this paper attempt to address?