کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
452955 694674 2013 12 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
CoCoSpot: Clustering and recognizing botnet command and control channels using traffic analysis
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
CoCoSpot: Clustering and recognizing botnet command and control channels using traffic analysis
چکیده انگلیسی

We present CoCoSpot, a novel approach to recognize botnet command and control channels solely based on traffic analysis features, namely carrier protocol distinction, message length sequences and encoding differences. Thus, CoCoSpot can deal with obfuscated and encrypted C&C protocols and complements current methods to fingerprint and recognize botnet C&C channels. Using average-linkage hierarchical clustering of labeled C&C flows, we show that for more than 20 recent botnets and over 87,000 C&C flows, CoCoSpot can recognize more than 88% of the C&C flows at a false positive rate below 0.1%.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computer Networks - Volume 57, Issue 2, 4 February 2013, Pages 475–486
نویسندگان
, , ,