Revisiting Node Injection of P2P Botnet.

Jia Yan,Lingyun Ying,Yi Yang,Purui Su,Qi Li,Hui Kong,Dengguo Feng
DOI: https://doi.org/10.1007/978-3-319-11698-3_10
2014-01-01
Abstract:Botnet armed with P2P protocol is especially robust against various attacks used to be very effective against centralized network. It's especially significant to enhance our understanding of unstructured P2P Botnets which prove to be resilient against various dismantle efforts. Node injection technique is quite effective in enumerating infected hosts from P2P Botnets, but no previous work has investigated the effectiveness of this method in a quantitative manner. In this paper, we propose a peer popularity boosting algorithm to put the popularity of injected peer under control, and a method to tune the node injection rate to achieve better compromise between consumed bandwidth and completeness of node enumeration. Furthermore, we evaluate our methods with varied level of node injections on three live P2P Botnets, the result shows that our method is quite effective in boosting and manipulating injected peer's popularity. In contrast to other methods without manipulation of injected peer's magnitude of dispersion in network, our method not only unlock the full potential of node injections, but also could be adapted to measurements of various needs.
What problem does this paper attempt to address?