Stegobot: a covert social network botnet

Shishir Nagaraja*, Amir Houmansadr, Pratch Piyawongwisal, Vijit Singh, Pragya Agarwal, Nikita Borisov

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution book

59 Citations (Scopus)

Abstract

We propose Stegobot, a new generation botnet that communicates over probabilistically unobservable communication channels. It is designed to spread via social malware attacks and steal information from its victims. Unlike conventional botnets, Stegobot traffic does not introduce new communication endpoints between bots. Instead, it is based on a model of covert communication over a social-network overlay - bot to botmaster communication takes place along the edges of a social network. Further, bots use image steganography to hide the presence of communication within image sharing behavior of user interaction. We show that it is possible to design such a botnet even with a less than optimal routing mechanism such as restricted flooding. We analyzed a real-world dataset of image sharing between members of an online social network. Analysis of Stegobot's network throughput indicates that stealthy as it is, it is also functionally powerful - capable of channeling fair quantities of sensitive data from its victims to the botmaster at tens of megabytes every month.

Original languageEnglish
Title of host publicationInformation Hiding - 13th International Conference, IH 2011, Revised Selected Papers
EditorsT. Filler , T. Pevný , S. Craver , A. Ker
Place of PublicationBerlin
PublisherSpringer
Pages299-313
Number of pages15
Volume6958
ISBN (Print)9783642241772
DOIs
Publication statusPublished - 26 Sept 2011
Event13th International Conference on Information Hiding, IH 2011 - Prague, Czech Republic
Duration: 18 May 201120 May 2011

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume6958 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference13th International Conference on Information Hiding, IH 2011
Country/TerritoryCzech Republic
CityPrague
Period18/05/1120/05/11

Keywords

  • social network
  • online social network
  • image steganography
  • stego image
  • covert channel
  • behavioral research
  • communication
  • network routing
  • computer aided network analysis

Fingerprint

Dive into the research topics of 'Stegobot: a covert social network botnet'. Together they form a unique fingerprint.

Cite this