A survey on real world botnets and detection mechanisms
2014; Institute of Advanced Engineering and Science (IAES); Volume: 3; Issue: 2 Linguagem: Inglês
ISSN
2089-3299
AutoresSomayeh Soltani, Seyed Amin Hosseini Seno, Maryam Nezhadkamali, Rahmat Budiarto,
Tópico(s)Advanced Malware Detection Techniques
ResumoMitigating the destructive effect of botnets is a concern of security scholars. Though various mechanisms are proposed for botnets detection, real world botnets still survive and do their harmful operations. Botnets have developed new evasion techniques and covert communication channels. Knowing the characteristics of real world botnets helps security researchers in developing more robust detection methods. There are some surveys in the literature that study botnet detection methods; however they do not advert to real world botnets a lot. In this paper, we study various aspects of several real world botnets, i.e. Conficker, Kraken, Rustock, Storm, TDL4, Torpig, Waledac, Zeus and P2P Zeus. Architecture, protocol, type of infection, communication interval, attacks and evasion techniques of these botnets are probed in this paper. Moreover, studies on mitigation and detection of various aspects of botnets and new trends in botnet communication channels are reviewed.
Referência(s)