Please use this identifier to cite or link to this item: http://openarchive.nure.ua/handle/document/1950
Title: Discovering New Indicators for Botnet Traffic Detection
Authors: Adamov, Alexander
Hahanov, Vladimir
Carlsson, Anders
Keywords: botnet
detection
IDS
Individual Cyberspace
traffic
encryption
gnature
Indicator-of-Compromise
Issue Date: 2014
Publisher: EWDTS
Citation: Alexander Adamov Discovering New Indicators for Botnet Traffic Detection/Alexander Adamov, Vladimir Hahanov, Anders Carlsson//Proceedings of IEEE East-West Design & Test Symposium (EWDTS’2014)
Abstract: Botnets became the powerful cyber weapon that involves tens of millions of infected computers – “cyber zombies” – all over the world. The security industry makes efforts to prevent spreading botnets and compromising an Individual Cyberspace (IC)[1] of users in such way. However, botnets continue existing despite numerous takedowns initiated by antivirus companies, Microsoft, FBI, Europol and others. In this paper we investigate existed methods of traffic detection represented mostly by IDS system and discover new indicators that can be utilized for improving botnet traffic detection. To do this we analyse the most prevalent backdoors communication protocols that stay behind of the popular botnets. As a result, we extracted new data that might be used in detection routines of IDS (Intrusion Detection System). An objective of the study is mining new indicators of compromise from botnet traffic and using them to identify cyber-attacks on IC. The analysis method assumes analysis of a communication protocol of the top botnet backdoors. The discovered results that can be used to improve detection of infected hosts in a local network are presented in this paper. A modern society sees an increase in cyber attacks that is attempted to be mitigated by antivirus and other security companies. Nowadays an Individual Cyberspace is highly vulnerable against identity and money theft on the Internet. The most spread and dangerous threat for every Internet user is botnets that conquer more and more user computers and turning them into “cyber zombies”. Despite numerous takedown attempts the botnets are still alive and continue successfully stealing users’ credentials. Detecting botnet is a complex task because of two major reasons: using encryption for transferred data, involving numerous infected bots as proxy layers to deliver data to C&C. Currently the botnets became an unbreakable despite of recent takedowns of Kelihos and Zeus botnets because of distributed nature of botnets and using several layers of proxy-bots. The latest Tovar Operation jointly run by FBI, NCA, Europol and antivirus companies in the beginning of June disconnected Zeus bots from mothership C&C(Command and Control) servers.
URI: http://openarchive.nure.ua/handle/document/1950
Appears in Collections:Кафедра автоматизації проектування обчислювальної техніки (АПОТ)

Files in This Item:
File Description SizeFormat 
Адамов_EWDTS_2014.pdf1.07 MBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Admin Tools