Peer-to-Peer BotNet Traffic Analysis and Detection

  • Han, Dongseok
  • Han, Kyoung Soo
  • Kang, Boojoong
  • Han, Hwansoo
  • Im, Eul Gyu
Citations

WEB OF SCIENCE

1
Citations

SCOPUS

1

초록

One of the most serious threats against the Internet is attacks from botnets. The botnet amplifies the intensity of attacks through the cooperation of compromised hosts. Recently, some botnets have evolved into a decentralized structure like peer-to-peer (P2P) network. Without fixed C&C servers, P2P botnets are difficult to detect. In this paper, we proposed a multi-step P2P botnet detection system based on botnets' probing characteristics. The first step uses entropy of information theory to detect the compromised hosts with great performance, and the second step (duplication ratio) concentrates on decreasing false positives. The experiment results show better false positive rate than a previous system.

키워드

Botnet detectionNetwork SecurityPeer-to-Peer (P2P) BotnetTraffic Analysis
제목
Peer-to-Peer BotNet Traffic Analysis and Detection
저자
Han, DongseokHan, Kyoung SooKang, BoojoongHan, HwansooIm, Eul Gyu
발행일
2012-04
유형
Article
저널명
Information
15
4
페이지
1605 ~ 1624