Disclosure: detecting botnet command and control servers through large-scale NetFlow analysis

Disclosure: detecting botnet command and control servers through large-scale NetFlow analysis
复制标题

DOI:
10.1145/2420950.2420969
复制
发表时间:
2012-12
期刊:
--
影响因子:
--
通讯作者:
Leyla Bilge;D. Balzarotti;William K. Robertson;E. Kirda;Christopher Krügel
Leyla Bilge;D. Balzarotti;William K. Robertson;E. Kirda;Christopher Krügel
中科院分区:
其他
文献类型:
--
作者:
Leyla Bilge;D. Balzarotti;William K. Robertson;E. Kirda;Christopher Krügel

文献摘要

被引文献

相似文献

僵尸网络仍然是互联网上的一个重大问题。因此,大量研究都集中在检测和减轻僵尸网络影响的方法上。阻碍开发有效的大规模、广域僵尸网络检测系统的两个主要因素看似相互矛盾。一方面,技术和管理限制导致普遍无法获得有助于大规模僵尸网络检测的原始网络数据。另一方面,即使有了这些数据,在这种规模下进行实时处理也将是一项艰巨的挑战。与原始网络数据相比,NetFlow 数据可以广泛获取。但是,NetFlow 数据对进行准确的僵尸网络检测提出了一些挑战。在本文中,我们介绍了大型广域僵尸网络检测系统 Disclosure,该系统结合了多种新技术,克服了使用 NetFlow 数据所带来的挑战。特别是,我们确定了几组特征,使 Disclosure 能够可靠地区分 C&C 渠道和使用 NetFlow 记录的良性流量(即流量大小、客户端访问模式和时间行为)。为了降低 Disclosure 的误报率,我们在系统的检测程序中加入了一些外部信誉评分。最后,我们通过两个大型真实网络对 Disclosure 进行了广泛评估。我们的评估表明,Disclosure 能够在每天数十亿流量的数据集上对僵尸网络 C&C 通道进行实时检测。
Botnets continue to be a significant problem on the Internet. Accordingly, a great deal of research has focused on methods for detecting and mitigating the effects of botnets. Two of the primary factors preventing the development of effective large-scale, wide-area botnet detection systems are seemingly contradictory. On the one hand, technical and administrative restrictions result in a general unavailability of raw network data that would facilitate botnet detection on a large scale. On the other hand, were this data available, real-time processing at that scale would be a formidable challenge. In contrast to raw network data, NetFlow data is widely available. However, NetFlow data imposes several challenges for performing accurate botnet detection. In this paper, we present Disclosure, a large-scale, wide-area botnet detection system that incorporates a combination of novel techniques to overcome the challenges imposed by the use of NetFlow data. In particular, we identify several groups of features that allow Disclosure to reliably distinguish C&C channels from benign traffic using NetFlow records (i.e., flow sizes, client access patterns, and temporal behavior). To reduce Disclosure's false positive rate, we incorporate a number of external reputation scores into our system's detection procedure. Finally, we provide an extensive evaluation of Disclosure over two large, real-world networks. Our evaluation demonstrates that Disclosure is able to perform real-time detection of botnet C&C channels over datasets on the order of billions of flows per day.