Open Access. Powered by Scholars. Published by Universities.®

Engineering Commons

Open Access. Powered by Scholars. Published by Universities.®

Series

PDF

Computer Sciences

2008

Botnet

Articles 1 - 1 of 1

Full-Text Articles in Engineering

Botsniffer: Detecting Botnet Command And Control Channels In Network Traffic, Guofei Gu, Junjie Zhang, Wenke Lee Feb 2008

Botsniffer: Detecting Botnet Command And Control Channels In Network Traffic, Guofei Gu, Junjie Zhang, Wenke Lee

Computer Science and Engineering Faculty Publications

Botnets are now recognized as one of the most serious security threats. In contrast to previous malware, botnets have the characteristic of a command and control (C&C) channel. Botnets also often use existing common protocols, e.g., IRC, HTTP, and in protocol-conforming manners. This makes the detection of botnet C&C a challenging problem. In this paper, we propose an approach that uses network-based anomaly detection to identify botnet C&C channels in a local area network without any prior knowledge of signatures or C&C server addresses. This detection approach can identify both the C&C servers and infected hosts in the network. Our …