PeerShark: Detecting Peer-to-Peer Botnets by Tracking Conversations

PeerShark: Detecting Peer-to-Peer Botnets by Tracking Conversations
复制标题

DOI:
10.1109/spw.2014.25
复制
发表时间:
2014-05
期刊:
2014 IEEE Security and Privacy Workshops
影响因子:
--
通讯作者:
Pratik Narang;S. Ray;C. Hota;V. Venkatakrishnan
Pratik Narang;S. Ray;C. Hota;V. Venkatakrishnan
中科院分区:
其他
文献类型:
--
作者:
Pratik Narang;S. Ray;C. Hota;V. Venkatakrishnan

文献摘要

被引文献

相似文献

点对点 (P2P) 僵尸网络的分散性质使其难以检测。它们的分布式特性还表现出针对删除尝试的弹性。此外,更聪明的机器人的通信模式是隐秘的,并且躲避寻找异常网络或通信行为的标准发现技术。在本文中,我们提出了 PeerShark,这是一种检测 P2P 僵尸网络流量并将其与网络中良性 P2P 流量区分开来的新颖方法。我们没有使用传统的五元组“基于流”检测方法,而是使用二元组“基于会话”方法,该方法不考虑端口、协议,并且不需要深度数据包检查。 PeerShark还可以对不同的P2P应用程序进行分类,准确率超过95%。
The decentralized nature of Peer-to-Peer (P2P) botnets makes them difficult to detect. Their distributed nature also exhibits resilience against take-down attempts. Moreover, smarter bots are stealthy in their communication patterns, and elude the standard discovery techniques which look for anomalous network or communication behavior. In this paper, we propose PeerShark, a novel methodology to detect P2P botnet traffic and differentiate it from benign P2P traffic in a network. Instead of the traditional 5-tuple 'flow-based' detection approach, we use a 2-tuple 'conversation-based' approach which is port-oblivious, protocol-oblivious and does not require Deep Packet Inspection. PeerShark could also classify different P2P applications with an accuracy of more than 95%.