Uma Arquitetura Baseada em Assinaturas para Mitigação de Botnets

  • João Marcelo Ceron UFRGS
  • Lisandro Zambenedetti Granville UFRGS
  • Liane Margarida Rockenbach Tarouco UFRGS

Abstract


Botnets are one of the most serious security threats of the current Internet. Such threats are characterized by being very dynamic, frequently incorporating into their structure new features whose goal is to decrease the efficiency of systems like anti-viruses and IDSes. This paper presents an architecture for a signature-based tool for botnet detection and mitigation. Identifying botnets' signatures in an automated fashion helps to detect compromised machines and to mitigate the damages caused by botnets.

References

CAIDA (2010). The Cooperative Association for Internet Data Analysis. Disponível em: http://www.caida.org. Acesso em: Julho de 2010.

Ceron, J., Granville, L. Z., and Tarouco, L. (2009). Taxonomia de malwares: Uma avaliação dos malwares automaticamente propagados na rede. In SBSeg 2009 Artigos Completos/Full Papers.

Cisco (2010). Cisco Netflow Cisco Systems.

GeoIP (2010). GeoIP API Location from IP. Disponível em: http://www.geoipapi.com/. Acesso em: Junho de 2010.

Goebel, J. and Holz, T. (2007). Rishi: identify bot contaminated hosts by irc nickname evaluation. In HotBots’07: Proceedings of the first conference on First Workshop on Hot Topics in Understanding Botnets, Berkeley, CA, USA. USENIX Association.

Gu, G., Perdisci, R., Zhang, J., and Lee, W. (2008a). Botminer: clustering analysis of network traffic for protocoland structure-independent botnet detection. In SS’08: Proceedings of the 17th conference on Security symposium, pages 139–154, Berkeley, CA, USA. USENIX Association.

Gu, G., Porras, P., Yegneswaran, V., Fong, M., and Lee, W. (2007). BotHunter: Detecting malware infection through ids-driven dialog correlation. In Proceedings of the 16th USENIX Security Symposium (Security’07).

Gu, G., Zhang, J., and Lee, W. (2008b). BotSniffer: Detecting botnet command and control channels in network traffic. In Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS’08).

Holz, T., Steiner, M., Dahl, F., Biersack, E., and Freiling, F. (2008). Measurements and mitigation of peer-to-peer-based botnets: a case study on storm worm. In LEET’08: Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats, pages 1–9, Berkeley, CA, USA. USENIX Association.

Kreibich, C., Kanich, C., Levchenko, K., Enright, B., Voelker, G. M., Paxson, V., and Savage, S. (2009). Spamcraft: An inside look at spam campaign orchestration. In Proceedings of the Second USENIX Workshop on Large-scale Exploits and Emergent Threats (LEET), Boston, USA.

Nazario, J. and Holz, T. (2008). As the net churns: Fast-flux botnet observations. In 3rd International Conference on Malicious and Unwanted Software Malware’08.

Nepenthes (2010). Nepenthes finest collection . Disponível em: http://nepenthes.carnivore.it. Acesso em: Junho 2010.

Wang, P., Wu, L., Cunningham, R., and Zou, C. C. (2010). Honeypot detection in advanced botnet attacks. Int. J. Inf. Comput. Secur., 4(1):30–51.

Wurzinger, P., Bilge, L., Holz, T., Goebel, J., Kruegel, C., and Kirda, E. (2009). Automatically generating models for botnet detection tr-iseclab-0609-001. In Lecture Notes in Computer Science, pages 108–125.
Published
2010-10-11
CERON, João Marcelo; GRANVILLE, Lisandro Zambenedetti; TAROUCO, Liane Margarida Rockenbach. Uma Arquitetura Baseada em Assinaturas para Mitigação de Botnets. In: BRAZILIAN SYMPOSIUM ON CYBERSECURITY (SBSEG), 10. , 2010, Fortaleza. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2010 . p. 105-118. DOI: https://doi.org/10.5753/sbseg.2010.20581.

Most read articles by the same author(s)

1 2 > >>