허니넷을 이용한 P2P 기반 Storm 봇넷의 트래픽 분석

The Traffic Analysis of P2P-based Storm Botnet using Honeynet

초록

Recently, the cyber-attacks using botnets are being increased. Because these attacks pursue the money, the criminal aspect is also being increased. There are spreading of spam mail, DDoS(Distributed Denial of Service) attacks, propagations of malicious codes and malwares, phishings, leaks of sensitive informations as cyber-attacks that used botnets. There are many studies about detection and mitigation techniques against centralized botnets, namely IRC and HTTP botnets. However, P2P botnets are still in an early stage of their studies. In this paper, we analyzed the traffics of the Peacomm bot that is one of P2P-based storm bot by using honeynet which is utilized in active analysis of network attacks. As a result, we could see that the Peacomm bot sends a large number of UDP packets to the zombies in wide network through P2P. Furthermore, we could know that the Peacomm bot makes the scale of botnet maintained and extended through these results. We expect that these results are used as a basis of detection and mitigation techniques against P2P botnets.

키워드

P2P BotnetStorm BotnetBotnet Traffic AnalysisHoneynet
제목
허니넷을 이용한 P2P 기반 Storm 봇넷의 트래픽 분석
제목 (타언어)
The Traffic Analysis of P2P-based Storm Botnet using Honeynet
저자
한경수임광혁임을규
발행일
2009-08
저널명
정보보호학회논문지
19
4
페이지
51 ~ 61