Publication | Closed Access
A Novel IRC Botnet Detection Method Based on Packet Size Sequence
23
Citations
17
References
2010
Year
Unknown Venue
Hardware SecurityQuasi-periodicity DegreeTcp ConversationDdos DetectionEngineeringInternet Traffic AnalysisIntrusion Detection SystemInformation SecurityDenial-of-service AttackInformation ForensicsPacket Size SequenceBotnet DetectionComputer ScienceNetwork Traffic MeasurementApproximate Periodicity
Botnets have become a serious threat to Internet and are often deployed to control a large pool of zombies and perform notorious activities such as DDoS, information theft and spam sending. In this paper, a new method is developed for detecting IRC botnets by analyzing the characteristic of packet size sequence of the TCP conversation between IRC zombies and their command and control (C&C) servers. In comparison with IRC chat, the TCP conversations within IRC botnets show a nature of approximate periodicity defined as quasi-periodicity in this paper. A simple yet effective detection method is presented to detect IRC botnets by measuring the quasi-periodicity degree and packet average size of IRC conversations based on ukkonen algorithm. We evaluated our method using real-world IRC botnet traces captured from honeynet. The results show that our method can detect real-world IRC botnets from IRC traffic with high accuracy and has a low false positive rate.
| Year | Citations | |
|---|---|---|
Page 1
Page 1