BotFinder: Finding Bots in Network Traffic Without Deep Packet Inspection

2012 | Konferenzbeitrag

Spring zu: Zitieren & Links | Dokumente & Medien | Details | Versionsgeschichte

Zitiervorschlag

​BotFinder: ​Finding Bots in Network Traffic Without Deep Packet Inspection​
Tegeler, F. ; Fu, X. ; Vigna, G. & Kruegel, C.​ (2012)
​Proceedings of the 8th international conference on Emerging networking experiments and technologies pp. 349​-360. ​CoNEXT '12​, New York, NY, USA.
ACM. DOI: https://doi.org/10.1145/2413176.2413217 

Dokumente & Medien

Lizenz

GRO License GRO License

Details

Autor(en)
Tegeler, Florian ; Fu, Xiaoming ; Vigna, Giovanni; Kruegel, Christopher
Zusammenfassung
Bots are the root cause of many security problems on the Internet, as they send spam, steal information from infected machines, and perform distributed denial-of-service attacks. Many approaches to bot detection have been proposed, but they either rely on end-host installations, or, if they operate on network traffic, require deep packet inspection for signature matching. In this paper, we present BotFinder, a novel system that detects infected hosts in a network using only high-level properties of the bot's network traffic. BotFinder does not rely on content analysis. Instead, it uses machine learning to identify the key features of command-and-control communication, based on observing traffic that bots produce in a controlled environment. Using these features, BotFinder creates models that can be deployed at network egress points to identify infected hosts. We trained our system on a number of representative bot families, and we evaluated BotFinder on real-world traffic datasets -- most notably, the NetFlow information of a large ISP that contains more than 25 billion flows. Our results show that BotFinder is able to detect bots in network traffic without the need of deep packet inspection, while still achieving high detection rates with very few false positives.
Erscheinungsdatum
2012
Herausgeber
ACM
Konferenz
CoNEXT '12
ISBN
978-1-4503-1775-7
Veranstaltungsort
New York, NY, USA
Veranstaltungsstart
2012-12-10
Veranstaltungsende
2012-12-13
Sprache
Englisch

Export Metadaten

Referenzen

Zitationen


Social Media