A multifaceted approach to understanding the botnet phenomenon

A multifaceted approach to understanding the botnet phenomenon
复制标题

DOI:
10.1145/1177080.1177086
复制
发表时间:
2006-10
期刊:
--
影响因子:
--
通讯作者:
M. Rajab;J. Zarfoss;F. Monrose;A. Terzis
M. Rajab;J. Zarfoss;F. Monrose;A. Terzis
中科院分区:
其他
文献类型:
--
作者:
M. Rajab;J. Zarfoss;F. Monrose;A. Terzis

文献摘要

被引文献

相似文献

长期以来,学术界一直承认恶意僵尸网络的存在,但到目前为止,人们对这些分布式计算平台的行为知之甚少。据我们所知,僵尸网络的行为从未被系统地研究过,僵尸网络在互联网上的流行大多是一个谜,僵尸网络的生命周期还有待建模。不确定性比比皆是。在本文中,我们试图通过构建一个多方面的分布式测量基础设施来消除围绕僵尸网络的迷雾。在三个多月的时间里,我们使用这个基础设施跟踪了192个独特的IRC僵尸网络,大小从几百到几千个受感染的终端主机不等。我们的结果表明,僵尸网络是有害互联网流量的主要贡献者-从我们的分布式暗网观察到的所有恶意连接尝试中,有27%可以直接归因于与僵尸网络相关的传播活动。此外,在我们检查的800,000个DNS域中,我们发现有11%的域名存在僵尸网络感染的证据,这表明僵尸网络受害者具有高度的多样性。总体而言,这些结果不仅突出了僵尸网络的重要性,还提供了深刻的见解,可能有助于进一步研究以遏制这一现象。
The academic community has long acknowledged the existence of malicious botnets, however to date, very little is known about the behavior of these distributed computing platforms. To the best of our knowledge, botnet behavior has never been methodically studied, botnet prevalence on the Internet is mostly a mystery, and the botnet life cycle has yet to be modeled. Uncertainty abounds. In this paper, we attempt to clear the fog surrounding botnets by constructing a multifaceted and distributed measurement infrastructure. Throughout a period of more than three months, we used this infrastructure to track 192 unique IRC botnets of size ranging from a few hundred to several thousand infected end-hosts. Our results show that botnets represent a major contributor to unwanted Internet traffic - 27% of all malicious connection attempts observed from our distributed darknet can be directly attributed to botnet-related spreading activity. Furthermore, we discovered evidence of botnet infections in 11% of the 800,000 DNS domains we examined, indicating a high diversity among botnet victims. Taken as a whole, these results not only highlight the prominence of botnets, but also provide deep insights that may facilitate further research to curtail this phenomenon.