A Scalable Architecture for Persistent Botnet Tracking

نویسنده

  • Jay Zarfoss
چکیده

The botnet phenomenon has recently garnered attention throughout both academia and industry. Unfortunately, botnets are still a mystery. In fact, today, very little is known about even the most basic botnet properties, such as size, growth, or demographics. The primary reason for this lack of knowledge is the fact that the existing approaches for measuring such properties are simply inadequate; honeypots [30], even those with advanced virtualization [40], cannot scale to the task of botnet tracking, while silent drones do not offer the dynamism necessary to persistently track botnets. Furthermore, both of these techniques provide only one, internal, view of the botnet. As we will demonstrate, this single view will often fail to provide relevant information on botnet size or diversity. Indeed, the fog has yet to clear. In order to gain a firm understanding of botnet dynamics, we have developed a lightweight infrastructure that overcomes many of the problems of prior approaches. Our infrastructure follows the entire life cycle of the botnet, beginning with the capture of botnet executables from various Internet vantage points. We apply novel techniques to automatically learn the network properties (or so-called “dialects”) of the bot binary, and we subsequently transfer this information to a specialized robot. Similar, in spirit, to the aforementioned drone, our scalable robot joins live botnets and offers an insider’s view of the malicious network. However, the similarities end here. Unlike a drone, the robot offers real-time responsiveness previously available only with high-interaction honeypots, thus avoiding botmaster scrutiny by intelligently acknowledging botmasters’ commands. Moreover, unlike lightweight tracking systems of the past, our approach allows for long term tracking of the migratory botnet – a salient variety of botnet which, at present, remains conspicuously under-documented.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Dynamic configuration and collaborative scheduling in supply chains based on scalable multi-agent architecture

Due to diversified and frequently changing demands from customers, technological advances and global competition, manufacturers rely on collaboration with their business partners to share costs, risks and expertise. How to take advantage of advancement of technologies to effectively support operations and create competitive advantage is critical for manufacturers to survive. To respond to these...

متن کامل

SIBRA: Scalable Internet Bandwidth Reservation Architecture

This paper proposes a Scalable Internet Bandwidth Reservation Architecture (SIBRA) as a new approach against DDoS attacks, which, until now, continue to be a menace on today’s Internet. SIBRA provides scalable inter-domain resource allocations and botnet-size independence, an important property to realize why previous defense approaches are insufficient. Botnetsize independence enables two end ...

متن کامل

Monitoring persistent items in the union of distributed streams

A persistent item in a stream is one that occurs regularly in the stream without necessarily contributing significantly to the volume of the stream. Persistent items are often associated with anomalies in network streams, such as botnet traffic and click fraud. While it is important to track persistent items in an online manner, it is challenging to zero-in on such items in a massive distribute...

متن کامل

Botnet Tracking Tools

Botnets are a serious threat to internet security. Botnets consist of networked collections of compromised machines called robots or ‘bots’ for short. Bots are also called ‘zombies,’ and botnets are also called ‘zombie armies.’ Bots are controlled by nodes called ‘botmasters’ or ‘botherders.’ Bots are infected with malicious code that performs work on behalf of the botmaster or botherder. Botne...

متن کامل

Botnet Tracking Tools

Botnets are a serious threat to internet security. Botnets consist of networked collections of compromised machines called robots or ‘bots’ for short. Bots are also called ‘zombies,’ and botnets are also called ‘zombie armies.’ Bots are controlled by nodes called ‘botmasters’ or ‘botherders.’ Bots are infected with malicious code that performs work on behalf of the botmaster or botherder. Botne...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007