Abstract
Botnets are one of the most threatening adversaries over the Internet due in large part to the difficulty of identifying botnet traffic patterns. Also, botnets are a prevalent and continuously growing method for conducting distributed attacks and identity theft. These attacks can include email spamming, distributed denial of service, port scanning, remote exploitation of vulnerabilities, and self-propagation to expand the botnet's size. The botnets can be used to scan infected hosts' machines and log keystrokes for sensitive data such as credit card and banking information, then relay gathered information to the botmasters. We have witnessed that existing signature-based detection and protection methods are ineffective in dealing with unknown bots. For these situations, a more proactive approach must be taken to gather and analyze botnets. In this paper, we introduce a network-centric attack management framework to learn more information about the bots by identifying malicious characteristics through the network traffic. Based on our framework, this paper focuses on our analysis method of IRC bots using IRC monitoring tool called IRC Sandman that observes IRC traffic and automatically downloads secondary injections from a command and control center. In addition, we briefly elaborate our findings and lessons learned.
Original language | English (US) |
---|---|
Title of host publication | 3rd International Conference on Information Warfare and Security |
Publisher | Academic Conferences Limited |
Pages | 1-9 |
Number of pages | 9 |
State | Published - 2008 |
Externally published | Yes |
Event | 3rd International Conference on Information Warfare and Security, ICIW 2008 - Omaha, NE, United States Duration: Apr 24 2008 → Apr 25 2008 |
Other
Other | 3rd International Conference on Information Warfare and Security, ICIW 2008 |
---|---|
Country/Territory | United States |
City | Omaha, NE |
Period | 4/24/08 → 4/25/08 |
Keywords
- Botnets
- IRC bot
- Network-centric attack
ASJC Scopus subject areas
- Information Systems
- Safety, Risk, Reliability and Quality