Botnet Detection by Monitoring Similar Communication Patterns
Hossein Rouhani Zeidanloo, Azizah Bt Abdul Manaf

TL;DR
This paper introduces a new general framework for detecting botnets by monitoring communication patterns, focusing on P2P and IRC-based botnets, without requiring prior knowledge of specific signatures.
Contribution
The paper provides a taxonomy of Botnet C&C channels and proposes a detection framework that does not depend on predefined signatures, enhancing adaptability.
Findings
Effective detection of P2P and IRC-based botnets
No prior signature knowledge needed for detection
Framework adaptable to evolving Botnet structures
Abstract
Botnet is most widespread and occurs commonly in today's cyber attacks, resulting in serious threats to our network assets and organization's properties. Botnets are collections of compromised computers (Bots) which are remotely controlled by its originator (BotMaster) under a common Command-and-Control (C&C) infrastructure. They are used to distribute commands to the Bots for malicious activities such as distributed denial-of-service (DDoS) attacks, spam and phishing. Most of the existing Botnet detection approaches concentrate only on particular Botnet command and control (C&C) protocols (e.g., IRC,HTTP) and structures (e.g., centralized), and can become ineffective as Botnets change their structure and C&C techniques. In this paper at first we provide taxonomy of Botnets C&C channels and evaluate well-known protocols which are being used in each of them. Then we proposed a new…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting · Advanced Malware Detection Techniques
