Publinova

Detection of Botnet Command and Control Traffic by the Identification of Untrusted Destinations

product

Detection of Botnet Command and Control Traffic by the Identification of Untrusted Destinations


Beschrijving

We present a novel anomaly-based detection approach capable
of detecting botnet Command and Control traffic in an enterprise
network by estimating the trustworthiness of the traffic destinations.
A traffic flow is classified as anomalous if its destination identifier does
not origin from: human input, prior traffic from a trusted destination, or
a defined set of legitimate applications. This allows for real-time detection
of diverse types of Command and Control traffic. The detection
approach and its accuracy are evaluated by experiments in a controlled
environment.



Publicatiedatum
Type
Document
Gebruiksrecht
Alle rechten voorbehouden
Alle rechten voorbehouden
Toegangsrecht
OpenAccess
DOI
Niet bekend
Gepubliceerd in

Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, Pagina's: 174-182, ISBN: 978-3-319-23829-6