skip to main content
10.1145/2660267.2662369acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
poster

POSTER: A Hybrid Botnet Ecological Environment

Authors Info & Claims
Published:03 November 2014Publication History

ABSTRACT

Research into defense against botnets, especially countermeasures against the command and control (C&C) protocol, has become increasingly significant as several large-scale botnets have resulted in serious threats on the Internet. However, most existing research efforts lack safe and efficient analysis platforms for C&C protocol fuzzing. Moreover, owing to the complex triggering conditions of botnet behaviors, these analysis platforms are unable to discover some of the "potential" behaviors of bots. To be well prepared for future attacks, increasing number of researchers have begun to study advanced botnet designs that could be developed by botmasters in the near future; however, they need a relatively closed and controllable environment designed by researchers to quantitatively evaluate the capabilities of these next-generation botnets. Consequently, we propose the Hybrid Botnet Ecological Environment (HBEE), which aims to make bots expose as many of their execution paths as possible, in order to mine the C&C protocol vulnerabilities of bots as well as to evaluate the capability of advanced botnets. Our design can also prevent bots from causing harm to the real Internet by malicious flow filtration and C&C server spoofing. Our preliminary results show that HBEE can observe communication actions and produce accurate and comprehensive data about botnet behaviors and advanced botnet capabilities.

References

  1. Wang, P., Sparks, S., and Zou, C.C. An advanced hybrid peer to peer botnet. In Proceedings of the First Workshop on Hot Topics in Understanding Botnets. HotBots'07. 2007. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Xiang, C., Binxing, F., Jinqiao, S., Chaoge, L. Botnet triple-channel model: Towards resilient and efficient bidirectional communication botnets. In Security and Privacy in Communication Networks, Springer International Publishing. pp. 53--68, 2013.Google ScholarGoogle ScholarCross RefCross Ref
  3. John J. P., Moshchuk A., Gribble S.D., and Krishnamurthy A. Studying spamming botnets using Botlab {C}. 6th USENIX Symposium on Network Systems Design and Implementation. Berkeley, CA: USENIX Association, pp. 291--306, 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. Chia YC, Juan C. Botnet Infiltration: Finding Bugs in Botnet Command and Control{EB/OL}. 2009{2011--6--10}. http://www.eecs.berkeley.edu/~chiayuan/cs261Google ScholarGoogle Scholar

Index Terms

  1. POSTER: A Hybrid Botnet Ecological Environment

      Recommendations

      Comments

      Login options

      Check if you have access through your login credentials or your institution to get full access on this article.

      Sign in
      • Published in

        cover image ACM Conferences
        CCS '14: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security
        November 2014
        1592 pages
        ISBN:9781450329576
        DOI:10.1145/2660267

        Copyright © 2014 Owner/Author

        Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

        Publisher

        Association for Computing Machinery

        New York, NY, United States

        Publication History

        • Published: 3 November 2014

        Check for updates

        Qualifiers

        • poster

        Acceptance Rates

        CCS '14 Paper Acceptance Rate114of585submissions,19%Overall Acceptance Rate1,261of6,999submissions,18%

        Upcoming Conference

        CCS '24
        ACM SIGSAC Conference on Computer and Communications Security
        October 14 - 18, 2024
        Salt Lake City , UT , USA

      PDF Format

      View or Download as a PDF file.

      PDF

      eReader

      View online with eReader.

      eReader