Logo image
The analysis and identification of P2P botnet's traffic flows
Journal article

The analysis and identification of P2P botnet's traffic flows

Wernhuar Tarng, Li-Zhong Den, Kuo-Liang Ou and Mingteh Chen
International Journal of Communication Networks and Information Security, Vol.3(2), pp.138-148
2011

Abstract

Decision-tree model Network security Network traffic flows P2P botnets Computer Networks and Communications
As the advance of information and communication technologies, the Internet has become an integral part of human life. Although it can provide us with many convenient services, there also exist some potential risks for its users. For example, hackers may try to steal confidential data for illegal benefits, and they use a variety of methods to achieve the goal of attacks, e.g., Distributed Denial of Service (DDoS), Spam and Trojan. These methods require a large number of computers; hence, hackers often spread out malicious software to infect those computers with lower defense mechanisms. The infected computers will become the zombie computers in the botnets controlled by hackers. Thus, it is an important subject regarding network security to detect and defend against the botnets. Among them, the Peer-to-Peer (P2P) botnet is a new type of botnets with every zombie computer as a peer controlled by hackers and thus its defense is more difficult. The objective of this study is to identify the traffic flows produced by known or unknown malicious software for defending against P2P botnets. Based on the analysis of P2P network's traffic flows and the ASCII distribution in their packets, a mechanism containing six steps was proposed to identify the traffic flows of P2P botnets for locating the zombie computers, and finally restrain the computers from further infection.

Metrics

1 Record Views

Details

Logo image