Logo image
Automatic NIDS Rule Generating System for HTTP-like Botnet Detection
Thesis

Automatic NIDS Rule Generating System for HTTP-like Botnet Detection

Chang, Yung-Cheng
Masters, 國立清華大學, 資訊工程學系
2010

Abstract

網路安全 魁儡網路 病毒特徵 自動化 network security botnet detection malware signature automatic generation
With the popular and widely used of Internet, HTTP has become the main protocol of Internet and many network applications rely on it. Botnet also utilizes it as a covert channel through which to evade the firewall (FW) or network intrusion detection system (NIDS). NIDS is a mechanism to detect a Botnet but the creation of an IDS rule set usually requires significant professional manpower and research time. In general, for an experienced rule maker, it takes several hours to analyze only dozen of malign traffic. These restrictions may delay the best timing to stop the spreading of Botnet. Base on statement above, we developed an automatic rule generation system (ARGS) to speed up the processing time of generating corresponding rule set. The ARGS generates the corresponding NIDS rule efficiently and precisely from the input malign traffic (MT). We use Snort as our IDS for practical purpose and adopt the open Botnet rule set as rule base. In our experiments, the true positive rate and false positive rate of generated rule set is more than 99% and less than 0.1%. Besides, with the integration of support vector machine (SVM), we can further combine rules which are highly relevant and reduce the rules’ numbers into 85%~90% of original size. With this mechanism, we can use less rule numbers to detect equal or more malware traffic. Furthermore, we can reduce the processing time of NIDS by reducing the rules’ number. In our experiments, we can reduce 10% processing time by reducing 5% rules’ number. Besides, we apply the rules generated by ARGS in county-level TANet to evaluate the performance of rules. On average, there are about 10~15% rules are triggered every day, and there are about 21000 logs recorded every day. The statistics indicate that the rules generated by ARGS can efficiently stop spreading of malware.

Metrics

1 Record Views

Details

Logo image