首页> 外文会议>International Conference on Advanced Communication Technology >Design, deployment and use of HTTP-based botnet (HBB) testbed
【24h】

Design, deployment and use of HTTP-based botnet (HBB) testbed

机译:设计,部署和使用基于HTTP的僵尸网络(HBB)测试平台

获取原文

摘要

Botnet is one of the most widespread and serious malware which occur frequently in today's cyber attacks. A botnet is a group of Internet-connected computer programs communicating with other similar programs in order to perform various attacks. HTTP-based botnet is most dangerous botnet among all the different botnets available today. In botnets detection, in particularly, behavioural-based approaches suffer from the unavailability of the benchmark datasets and this lead to lack of precise results evaluation of botnet detection systems, comparison, and deployment which originates from the deficiency of adequate datasets. Most of the datasets in the botnet field are from local environment and cannot be used in the large scale due to privacy problems and do not reflect common trends, and also lack some statistical features. To the best of our knowledge, there is not any benchmark dataset available which is infected by HTTP-based botnet (HBB) for performing Distributed Denial of Service (DDoS) attacks against Web servers by using HTTP-GET flooding method. In addition, there is no Web access log infected by botnet is available for researchers. Therefore, in this paper, a complete test-bed will be illustrated in order to implement a real time HTTP-based botnet for performing variety of DDoS attacks against Web servers by using HTTP-GET flooding method. In addition to this, Web access log with http bot traces are also generated. These real time datasets and Web access logs can be useful to study the behaviour of HTTP-based botnet as well as to evaluate different solutions proposed to detect HTTP-based botnet by various researchers.
机译:僵尸网络是当今网络攻击中经常发生的最广泛,最严重的恶意软件之一。僵尸网络是一组与其他相似程序通信以执行各种攻击的与Internet连接的计算机程序。在当今可用的所有不同僵尸网络中,基于HTTP的僵尸网络是最危险的僵尸网络。特别是在僵尸网络检测中,基于行为的方法遭受基准数据集不可用的困扰,这导致缺乏对僵尸网络检测系统,比较和部署的精确结果进行评估,这是由于缺乏适当的数据集所致。僵尸网络领域中的大多数数据集都来自本地环境,由于隐私问题而无法大规模使用,并且不能反映共同的趋势,并且还缺少一些统计功能。据我们所知,没有可用的基准数据集被基于HTTP的僵尸网络(HBB)感染,用于通过使用HTTP-GET泛洪方法对Web服务器执行分布式拒绝服务(DDoS)攻击。此外,研究人员还没有被僵尸网络感染的Web访问日志。因此,在本文中,将说明一个完整的测试平台,以实现一个实时的基于HTTP的僵尸网络,以通过使用HTTP-GET泛洪方法对Web服务器执行各种DDoS攻击。除此之外,还会生成带有http bot跟踪的Web访问日志。这些实时数据集和Web访问日志对于研究基于HTTP的僵尸网络的行为以及评估由不同的研究人员提出的检测基于HTTP的僵尸网络的不同解决方案很有用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号