Close category search window
 

Detecting P2P Botnets Using a Multi-phased Flow Model

Sign In

Cookies must be enabled to login.After enabling cookies , please use refresh or reload or ctrl+f5 on the browser for the login options.

Formats Non-Member Member
$31 $13
Learn how you can qualify for the best price for this item!
Become an IEEE Member or Subscribe to
IEEE Xplore for exclusive pricing!
close button

puzzle piece

IEEE membership options for an individual and IEEE Xplore subscriptions for an organization offer the most affordable access to essential journal articles, conference papers, standards, eBooks, and eLearning courses.

Learn more about:

IEEE membership

IEEE Xplore subscriptions

5 Author(s)
Sang-Kyun Noh ; Appl. Security Technol. Team, Korea Inf. Security Agency, Seoul ; Joo-Hyung Oh ; Jae-Seo Lee ; Bong-Nam Noh
more authors

In this paper, we propose a useful method for modeling multi-phased flows of P2P botnet traffic. Botnets are becoming more sophisticated and more dangerous each day and attackers use the P2P protocol to avoid centralized botnet topologies. We focus on the feature that a peer bot generates multiple traffic to communicate with large number of remote peers. In this case, phased botnet flows have similar patterns, which occur at irregular intervals. We compress duplicated flows via flow grouping and construct a transition model of the clustered flows using a probability-based matrix. A flow state is decided by features consisting of; protocol, port, and traffic. Our model involves transition information about the state values. Finally, we use the likelihood ratio for detection. In the experimental evaluation, we show the efficiency of our proposed system with the SpamThru, Storm, and Nugache botnets.

Published in:
Digital Society, 2009. ICDS '09. Third International Conference on

Date of Conference: 1-7 Feb. 2009

Need Help?


IEEE Advancing Technology for Humanity About IEEE Xplore | Contact | Help | Terms of Use | Nondiscrimination Policy | Site Map | Privacy & Opting Out of Cookies

A not-for-profit organization, IEEE is the world's largest professional association for the advancement of technology.
© Copyright 2013 IEEE - All rights reserved. Use of this web site signifies your agreement to the terms and conditions.