Automatically Generating Models for Botnet Detection.ppt
《Automatically Generating Models for Botnet Detection.ppt》由会员分享,可在线阅读,更多相关《Automatically Generating Models for Botnet Detection.ppt(20页珍藏版)》请在麦多课文档分享上搜索。
1、Automatically Generating Models for Botnet Detection,Presenter: 葉倚任Authors: Peter Wurzinger, Leyla Bilge, Thorsten Holz, Jan Goebel, Christopher Kruegel, Engin KirdaEuropean Symposium on Research in Computer Security (ESORICS09),Outline,Introduction System Overview Model Generation Data Generating D
2、etection Models Evaluation Conclusion,Introduction,Two main kinds of network-based detection system Vertical correlation technique Detection of individual bots Checking traffic patterns, content of C&C traffic, and bot related activities. Require prior knowledge of C&C channels and propagation vecto
3、rs of bot Horizontal correlation technique Detection of a group of bots Based on network traffic Require that at two bots in the monitor networks,Introduction (contd),Characteristic behavior of a bot Receive commands from botmater Carry out some actions in response to these commands This paper propo
4、sed a two-stage detection model to leverage these two characteristics In the experiments, the authors generated 18 different bot families. 16 controlled via IRC, One via HTTP (Kraken) One via a peer-to-peer network (Storm Worm).,System Overview,Input of the system A collection of bot binaries Launch
5、 a bot in a controlled environment and record its network activities (traces) Identify the commands that this bot receives as well as its corresponding responses Translate observations into detection models Output of the system Detection models for different bot families,Detecting Procedure,Stateful
6、 model (two-stage detection) Checking if a bot command is sent If yes in stage 1, checking if the responses is above a threshold or not (e.g., the number of new connections opened by a host) Use content-based specifications to model commands (comparable to intrusion detection signatures) Use network
7、-based specifications to model responses (comparable to anomaly detection),Model Generation Data,Run each bot binary for a period of several days Locating bot responses Finding commands Extracting model generation data,Locating bot responses,Assumption: bot responses that lead to a change in network
8、 behavior Partition network traffic into consecutive time intervals of equal length For each time interval, define 8 normalized features (called traffic profile):,Locating bot responses (contd),Convert the traffic profiles (vectors) into time series data d(t) as follows:where is the sliding window s
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- AUTOMATICALLYGENERATINGMODELSFORBOTNETDETECTIONPPT

链接地址:http://www.mydoc123.com/p-378754.html