BotFinder: Finding Bots in Network Traffic Without Deep Packet Inspection

2012 | conference paper

Jump to: Cite & Linked | Documents & Media | Details | Version history

Cite this publication

​BotFinder: ​Finding Bots in Network Traffic Without Deep Packet Inspection​
Tegeler, F. ; Fu, X. ; Vigna, G. & Kruegel, C.​ (2012)
​Proceedings of the 8th international conference on Emerging networking experiments and technologies pp. 349​-360. ​CoNEXT '12​, New York, NY, USA.
ACM. DOI: https://doi.org/10.1145/2413176.2413217 

Documents & Media

License

GRO License GRO License

Details

Authors
Tegeler, Florian ; Fu, Xiaoming ; Vigna, Giovanni; Kruegel, Christopher
Abstract
Bots are the root cause of many security problems on the Internet, as they send spam, steal information from infected machines, and perform distributed denial-of-service attacks. Many approaches to bot detection have been proposed, but they either rely on end-host installations, or, if they operate on network traffic, require deep packet inspection for signature matching. In this paper, we present BotFinder, a novel system that detects infected hosts in a network using only high-level properties of the bot's network traffic. BotFinder does not rely on content analysis. Instead, it uses machine learning to identify the key features of command-and-control communication, based on observing traffic that bots produce in a controlled environment. Using these features, BotFinder creates models that can be deployed at network egress points to identify infected hosts. We trained our system on a number of representative bot families, and we evaluated BotFinder on real-world traffic datasets -- most notably, the NetFlow information of a large ISP that contains more than 25 billion flows. Our results show that BotFinder is able to detect bots in network traffic without the need of deep packet inspection, while still achieving high detection rates with very few false positives.
Issue Date
2012
Publisher
ACM
Conference
CoNEXT '12
ISBN
978-1-4503-1775-7
Conference Place
New York, NY, USA
Event start
2012-12-10
Event end
2012-12-13
Language
English

Reference

Citations


Social Media