Characterizing Bots' Remote Control Behavior

Characterizing Bots' Remote Control Behavior
复制标题

DOI:
10.1007/978-3-540-73614-1_6
复制
发表时间:
2007-07
期刊:
--
影响因子:
--
通讯作者:
Elizabeth Stinson;John C. Mitchell
Elizabeth Stinson;John C. Mitchell
中科院分区:
其他
文献类型:
--
作者:
Elizabeth Stinson;John C. Mitchell

文献摘要

被引文献

相似文献

僵尸网络是一个僵尸程序的集合,每个僵尸程序通常运行在一个受损的系统上,并通过一个“命令和控制”覆盖网络响应命令。我们调查机器人和良性程序的行为中可观察到的差异,重点是机器人对通过网络接收的数据的响应方式。我们的实验平台监视任意Win32二进制文件的执行,考虑通过网络接收的数据被污染,应用库调用级别的污染传播,并检查选定的系统调用的污染参数。作为进一步区分本地发起的动作和远程发起的动作的一种方式,我们捕获并传播本地用户输入的“干净度”(如通过键盘或鼠标接收的)。测试表明,主要的机器人家族(agobot,DSNXbot,evilbot,G-SySbot,sdbot,Spybot)与良性程序的行为分离具有低错误率。
A botnet is a collection of bots, each generally running on a compromised system and responding to commands over a “command-and-control” overlay network. We investigate observable differences in the behavior of bots and benign programs, focusing on the way that bots respond to data received over the network. Our experimental platform monitors execution of an arbitrary Win32 binary, considering data received over the network to be tainted, applying library-call-level taint propagation, and checking for tainted arguments to selected system calls. As a way of further distinguishing locally-initiated from remotely-initiated actions, we capture and propagate “cleanliness” of local user input (as received via the keyboard or mouse). Testing indicates behavioral separation of major bot families (agobot, DSNXbot, evilbot, G-SySbot, sdbot, Spybot) from benign programs with low error rate.