Botyacc: unified P2P botnet detection using behavioural analysis and graph analysis

Shishir Nagaraja

Research output: Chapter in Book/Report/Conference proceedingConference contribution book

12 Citations (Scopus)

Abstract

The detection and isolation of peer-to-peer botnets is an ongoing problem. We propose a novel technique for detecting P2P botnets. Detection is based on unifying behavioural analysis with structured graph analysis. First, our inference technique exploits a fundamental property of botnet design. Modern botnets use peer-to-peer communication topologies which are fundamental to botnet resilience. Second, our technique extends conventional graph-based detection by incorporating behavioural analysis into structured graph analysis, thus unifying graph-theoretic detection with behavioural detection under a single algorithmic framework. We carried out evaluation over real-world P2P botnet traffic and show that the resulting algorithm can localise the majority of bots with low false-positive rate.

Original languageEnglish
Title of host publicationComputer Security, ESORICS 2014 - 19th European Symposium on Research in Computer Security, Proceedings
EditorsM. Kutyłowski, J. Vaidya
Place of PublicationCham
PublisherSpringer-Verlag
Pages439-456
Number of pages18
Volume8713
EditionPART 2
ISBN (Print)9783319112114
DOIs
Publication statusPublished - 1 Jan 2014
Event19th European Symposium on Research in Computer Security, ESORICS 2014 - Wroclaw, Poland
Duration: 7 Sep 201411 Sep 2014

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
NumberPART 2
Volume8713 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference19th European Symposium on Research in Computer Security, ESORICS 2014
Country/TerritoryPoland
CityWroclaw
Period7/09/1411/09/14

Keywords

  • behavioural analysis
  • botnet detection
  • graph theory
  • traffic analysis
  • security of data
  • security systems
  • malware

Fingerprint

Dive into the research topics of 'Botyacc: unified P2P botnet detection using behavioural analysis and graph analysis'. Together they form a unique fingerprint.

Cite this