• ثبت نام
    • ورود به سامانه
    مشاهده مورد 
    •   صفحهٔ اصلی
    • نشریات انگلیسی
    • The ISC International Journal of Information Security
    • Volume 10, Issue 1
    • مشاهده مورد
    •   صفحهٔ اصلی
    • نشریات انگلیسی
    • The ISC International Journal of Information Security
    • Volume 10, Issue 1
    • مشاهده مورد
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    BotRevealer: Behavioral Detection of Botnets based on Botnet Life-cycle

    (ندگان)پدیدآور
    Khoshhalpour, E.Shahriari, H. R.
    Thumbnail
    دریافت مدرک مشاهده
    FullText
    اندازه فایل: 
    575.8کیلوبایت
    نوع فايل (MIME): 
    PDF
    نوع مدرک
    Text
    ORIGINAL RESEARCH PAPER
    زبان مدرک
    English
    نمایش کامل رکورد
    چکیده
    Nowadays, botnets are considered as essential tools for planning serious cyber attacks. Botnets are used to perform various malicious activities such as DDoS attacks and sending spam emails. Different approaches are presented to detect botnets; however most of them may be ineffective when there are only a few infected hosts in monitored network, as they rely on similarity in bots activities to detect the botnet. In this paper, we present a host-based method that can detect individual bot-infected hosts. This approach is based on botnet life-cycle, which includes common symptoms of almost all types of botnet despite their differences. We analyze network activities of each process running on the host and propose some heuristics to distinguish behavioral patterns of bot process from legitimate ones based on statistical features of packet sequences and evaluating an overall security risk for it. To show the effectiveness of the approach, a tool named BotRevealer has been implemented and evaluated using real botnets and several popular applications. The results show that in spite of diversity of botnets, BotRevealer can effectively detect the bot process among other active processes.
    کلید واژگان
    Botnet Detection
    Botnet Life-Cycle
    Host-Based Intrusion Detection
    Heuristic Algorithm

    شماره نشریه
    1
    تاریخ نشر
    2018-01-01
    1396-10-11
    ناشر
    Iranian Society of Cryptology
    سازمان پدید آورنده
    Department of Computer Engineering and Information Technology, Amirkabir University of Technology, Tehran, Iran
    Department of Computer Engineering and Information Technology, Amirkabir University of Technology, Tehran, Iran

    شاپا
    2008-2045
    2008-3076
    URI
    https://dx.doi.org/10.22042/isecure.2017.81520.374
    http://www.isecure-journal.com/article_51289.html
    https://iranjournals.nlai.ir/handle/123456789/73336

    مرور

    همه جای سامانهپایگاه‌ها و مجموعه‌ها بر اساس تاریخ انتشارپدیدآورانعناوینموضوع‌‌هااین مجموعه بر اساس تاریخ انتشارپدیدآورانعناوینموضوع‌‌ها

    حساب من

    ورود به سامانهثبت نام

    آمار

    مشاهده آمار استفاده

    تازه ترین ها

    تازه ترین مدارک
    © کليه حقوق اين سامانه برای سازمان اسناد و کتابخانه ملی ایران محفوظ است
    تماس با ما | ارسال بازخورد
    قدرت یافته توسطسیناوب