Back to Search
Start Over
A Malware Beacon of Botnet by Local Periodic Communication Behavior
- Source :
- COMPSAC (2)
- Publication Year :
- 2018
- Publisher :
- IEEE, 2018.
-
Abstract
- Botnets are one of most serious threats in cyber security. Many previous studies have been proposed for botnet detection. Among those approaches, one of main tracks focuses on extracting informative features from network traffic flows. Nevertheless, most features of interest are extracted from the information of a single connection, such as flow duration, flow packet size etc. In this paper, we proposed an novel feature, which is able to detect a long-term behavior of botnets. More specifically, we aim to extract a malware beacon from the periodic communication between bots and bot master. Besides the regular communication pattern, we also explore several types of botnet behavior to leverage the effectiveness of the proposed feature. Our experimental results show that our proposed periodic communication signature could be one of effective features for detecting compromised devices.
- Subjects :
- Computer science
business.industry
ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS
Botnet
020206 networking & telecommunications
02 engineering and technology
computer.software_genre
Electronic mail
Server
0202 electrical engineering, electronic engineering, information engineering
Feature (machine learning)
Malware
Leverage (statistics)
020201 artificial intelligence & image processing
business
computer
Computer network
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- 2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC)
- Accession number :
- edsair.doi...........0632418de8cd661a7dc8c26f0312357a