За технічних причин Електронний архів Харківського національного університету радіоелектроніки «ElAr КhNURE» працює тільки на перегляд. Про відновлення роботи у повному обсязі буде своєчасно повідомлено.
 

Публікація:
Discovering New Indicators for Botnet Traffic Detection

dc.contributor.authorAdamov, A.
dc.contributor.authorHahanov, V.
dc.contributor.authorCarlsson, A.
dc.date.accessioned2016-09-02T06:30:13Z
dc.date.available2016-09-02T06:30:13Z
dc.date.issued2014
dc.description.abstractBotnets became the powerful cyber weapon that involves tens of millions of infected computers – “cyber zombies” – all over the world. The security industry makes efforts to prevent spreading botnets and compromising an Individual Cyberspace (IC)[1] of users in such way. However, botnets continue existing despite numerous takedowns initiated by antivirus companies, Microsoft, FBI, Europol and others. In this paper we investigate existed methods of traffic detection represented mostly by IDS system and discover new indicators that can be utilized for improving botnet traffic detection. To do this we analyse the most prevalent backdoors communication protocols that stay behind of the popular botnets. As a result, we extracted new data that might be used in detection routines of IDS (Intrusion Detection System). An objective of the study is mining new indicators of compromise from botnet traffic and using them to identify cyber-attacks on IC. The analysis method assumes analysis of a communication protocol of the top botnet backdoors. The discovered results that can be used to improve detection of infected hosts in a local network are presented in this paper. A modern society sees an increase in cyber attacks that is attempted to be mitigated by antivirus and other security companies. Nowadays an Individual Cyberspace is highly vulnerable against identity and money theft on the Internet. The most spread and dangerous threat for every Internet user is botnets that conquer more and more user computers and turning them into “cyber zombies”. Despite numerous takedown attempts the botnets are still alive and continue successfully stealing users’ credentials. Detecting botnet is a complex task because of two major reasons: using encryption for transferred data, involving numerous infected bots as proxy layers to deliver data to C&C. Currently the botnets became an unbreakable despite of recent takedowns of Kelihos and Zeus botnets because of distributed nature of botnets and using several layers of proxy-bots. The latest Tovar Operation jointly run by FBI, NCA, Europol and antivirus companies in the beginning of June disconnected Zeus bots from mothership C&C(Command and Control) servers.uk_UA
dc.identifier.citationAlexander Adamov Discovering New Indicators for Botnet Traffic Detection/Alexander Adamov, Vladimir Hahanov, Anders Carlsson//Proceedings of IEEE East-West Design & Test Symposium (EWDTS’2014)uk_UA
dc.identifier.urihttp://openarchive.nure.ua/handle/document/1950
dc.language.isoenuk_UA
dc.publisherEWDTSuk_UA
dc.subjectbotnetuk_UA
dc.subjectdetectionuk_UA
dc.subjectIDSuk_UA
dc.subjectIndividual Cyberspaceuk_UA
dc.subjecttrafficuk_UA
dc.subjectencryptionuk_UA
dc.subjectgnatureuk_UA
dc.subjectIndicator-of-Compromiseuk_UA
dc.titleDiscovering New Indicators for Botnet Traffic Detectionuk_UA
dc.typeArticleuk_UA
dspace.entity.typePublication

Файли

Оригінальний пакет
Зараз показано 1 - 1 з 1
Завантаження...
Зображення мініатюри
Назва:
Адамов_EWDTS_2014.pdf
Розмір:
1.04 MB
Формат:
Adobe Portable Document Format
Ліцензійний пакет
Зараз показано 1 - 1 з 1
Немає доступних мініатюр
Назва:
license.txt
Розмір:
9.42 KB
Формат:
Item-specific license agreed upon to submission
Опис: