Analysis of Attacker Behavior in Compromised Hosts During Command and Control
Farhan Sadique, Shamik Sengupta

TL;DR
This paper presents a proactive method for analyzing attacker behavior by examining command sequences in compromised hosts, using honeypots and an automated system to predict attacker actions without relying on network traffic analysis.
Contribution
It introduces a novel approach of analyzing attacker commands in compromised hosts and develops CYBEX-P for automated behavior prediction, differing from traditional network traffic analysis methods.
Findings
Successful prediction of attacker behavior from shell commands
Automated analysis system CYBEX-P developed and validated
Proactive detection method demonstrated effectiveness
Abstract
Traditional reactive approach of blacklisting botnets fails to adapt to the rapidly evolving landscape of cyberattacks. An automated and proactive approach to detect and block botnet hosts will immensely benefit the industry. Behavioral analysis of botnet is shown to be effective against a wide variety of attack types. Current works, however, focus solely on analyzing network traffic from and to the bots. In this work we take a different approach of analyzing the chain of commands input by attackers in a compromised host. We have deployed several honeypots to simulate Linux shells and allowed attackers access to the shells to collect a large dataset of commands. We have further developed an automated mechanism to analyze these data. For the automation we have developed a system called CYbersecurity information Exchange with Privacy (CYBEX-P). Finally, we have done a sequential analysis…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
