跳到主要导航 跳到搜索 跳到主要内容

A novel IRC botnet detection method based on packet size sequence

  • Tsinghua University
  • Xi'an Jiaotong University

科研成果: 书/报告/会议事项章节会议稿件同行评审

22 引用 (Scopus)

摘要

Botnets have become a serious threat to Internet and are often deployed to control a large pool of zombies and perform notorious activities such as DDoS, information theft and spam sending. In this paper, a new method is developed for detecting IRC botnets by analyzing the characteristic of packet size sequence of the TCP conversation between IRC zombies and their command and control (C&C) servers. In comparison with IRC chat, the TCP conversations within IRC botnets show a nature of approximate periodicity defined as quasi-periodicity in this paper. A simple yet effective detection method is presented to detect IRC botnets by measuring the quasi-periodicity degree and packet average size of IRC conversations based on ukkonen algorithm. We evaluated our method using real-world IRC botnet traces captured from honeynet. The results show that our method can detect real-world IRC botnets from IRC traffic with high accuracy and has a low false positive rate.

源语言英语
主期刊名2010 IEEE International Conference on Communications, ICC 2010
DOI
出版状态已出版 - 2010
活动2010 IEEE International Conference on Communications, ICC 2010 - Cape Town, 南非
期限: 23 5月 201027 5月 2010

出版系列

姓名IEEE International Conference on Communications
ISSN(印刷版)0536-1486

会议

会议2010 IEEE International Conference on Communications, ICC 2010
国家/地区南非
Cape Town
时期23/05/1027/05/10

学术指纹

探究 'A novel IRC botnet detection method based on packet size sequence' 的科研主题。它们共同构成独一无二的指纹。

引用此