Botnet Detection by Monitoring Common Network Behaviors: Botnet Detection by Monitoring Similar Communication Patterns
Автор:
Hossein Rouhani Zeidanloo, Sahar Rouhani, 104 стр., ISBN:
3848404753
Botnet is most widespread and occurs commonly in todaya? s cyber attacks, resulting in serious threats to our network assets and organizationa??s properties. Botnets are collections of compromised computers (Bots) which are remotely controlled by its originator (BotMaster) under a common Command-and-Control (C&C) infrastructure. They are used to distribute commands to the Bots for malicious activities such as distributed denial-of-service (DDoS) attacks, spam and phishing. Most of the existing Botnet detection approaches concentrate only on particular Botnet command and control (C&C) protocols (e.g.,IRC,HTTP) and structures (e.g., centralized), and can become ineffective as Botnets change their structure and C&C techniques. In this book at first we provide taxonomy of Botnets C&C channels and evaluate well-known protocols which are being used in each of them. Then we proposed a new general detection framework which currently focuses on P2P based and IRC based Botnets. This...
Под заказ: |
|
OZON.ru - 6282 руб.
|
Перейти
|
|
|