首页> 外文会议>IEEE Workshop on Secure Network Protocols >Implementation and Evaluation of Bot Detection Scheme based on Data Transmission Intervals
【24h】

Implementation and Evaluation of Bot Detection Scheme based on Data Transmission Intervals

机译:基于数据传输间隔的机器人检测方案的实现与评估

获取原文

摘要

Botnet is one of the most considerable issues in the world. A host infected with a bot is used for collecting personal information, launching DoS attacks, sending spam e-mail and so on. If such a machine exists in an organizational network, that organization will lose its reputation. We have to detect these bots existing in organizational networks immediately. Several network-based bot detection methods have been proposed; however, some traditional methods using payload analysis or signature-based detection scheme are undesirable in large amount of traffic. Also there is a privacy issue with looking into payloads, so we have to develop another scheme that is independent of payload analysis. In this paper, we propose a bot detection method which focuses on data transmission intervals. We distinguish human-operated clients and bots by their network behaviors. We assumed that a bot communicates with C&C server periodically and each interval of data transmission will be the same. We found that we can detect such behaviors by using clustering analysis to these intervals. We implemented our proposed algorithm and evaluated by testing normal IRC traffic and bot traffic captured in our campus network. We found that our method could detect IRC-based bots with low false positives.
机译:僵尸网络是世界上最相当大的问题之一。用机器人感染的主机用于收集个人信息,启动DOS攻击,发送垃圾邮件电子邮件等。如果这样的机器存在于组织网络中,则该组织将失去其声誉。我们必须立即检测到组织网络中存在的这些机器人。已经提出了几种基于网络的机器人检测方法;然而,在大量流量中,一些使用有效载荷分析或基于签名的检测方案的传统方法是不期望的。还有一个隐私问题,调查有效载荷,因此我们必须开发另一个独立于有效载荷分析的方案。在本文中,我们提出了一种侧重于数据传输间隔的BOT检测方法。我们通过网络行为区分人类经营的客户和机器人。我们假设机器人周期性地与C&C服务器通信,并且每个数据传输间隔都是相同的。我们发现我们可以通过使用聚类分析来检测这些行为。我们通过在校园网络中捕获的正常IRC流量和机器人流量来实现我们提出的算法并评估。我们发现我们的方法可以检测具有低误报的IRC基机器。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号