首页> 外文会议>International Conference on Reconfigurable Computing and FPGAs >Hardware isolation technique for IRC-based botnets detection
【24h】

Hardware isolation technique for IRC-based botnets detection

机译:基于IRC僵尸网络检测的硬件隔离技术

获取原文

摘要

Botnets are widely considered one of the most dangerous threats on the internet due to their modular and adaptive nature which makes them difficult to defend against. In contrast to previous generations of malicious codes, botnets have a command and control (C) infrastucture which allows them to be remotely controlled by their masters. A command and control infrastructure based on Internet Relay Chat protocol (IRC-based C) is one of the most popular C) infrastructures botnet creators use to deploy their botnets' malwares (IRC botnets). In this paper, we propose a novel approach to detect and eliminate IRC botnets. Our approach consists of inserting a reconfigurable hardware isolation layer between the network link and the target. Our reconfigurable hardware is an FPGA System-on-Chip (FPGA SoC) that uses both anomaly-based detection and signature-based detection approaches to identify IRC botnets. Since, unlike other viruses, to be able to freely communicate with their masters, botnets' primary objective is to disable any protection mechanism (firewalls, antivirus applications) found on the target machine; our hardware-based isolation infrastructure presents an improvement over existing software-based solutions.We evaluated our architecture codenamed BotPGA using real-world IRC botnets' non-encrypted network traces. The results show that BotPGA can detect real-world non-encrypted malicious IRC traffic and botnets with high accuracy.
机译:僵尸网络由于具有模块化和自适应性,因此难以防御,因此被广泛认为是互联网上最危险的威胁之一。与前几代恶意代码相比,僵尸网络具有命令和控制(C)基础结构,可让其主人对其进行远程控制。基于Internet中继聊天协议(基于IRC的C)的命令和控制基础结构是僵尸网络创建者用来部署其僵尸网络的恶意软件(IRC僵尸网络)的最流行的C)基础结构之一。在本文中,我们提出了一种检测和消除IRC僵尸网络的新颖方法。我们的方法包括在网络链接和目标之间插入可重新配置的硬件隔离层。我们的可重新配置硬件是FPGA片上系统(FPGA SoC),它使用基于异常的检测和基于签名的检测方法来识别IRC僵尸网络。由于与其他病毒不同,僵尸网络的主要目标是禁用目标计算机上发现的所有保护机制(防火墙,防病毒应用程序),从而可以与主病毒自由通信。我们的基于硬件的隔离基础结构对现有的基于软件的解决方案进行了改进。我们使用真实的IRC僵尸网络的非加密网络跟踪评估了代号为BotPGA的体系结构。结果表明,BotPGA可以高精度地检测实际的非加密恶意IRC流量和僵尸网络。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号