BotTrack: Tracking Botnets Using NetFlow and PageRank - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

BotTrack: Tracking Botnets Using NetFlow and PageRank

Résumé

With large scale botnets emerging as one of the major current threats, the automatic detection of botnet traffic is of high importance for service providers and large campus network monitoring. Faced with high speed network connections, detecting botnets must be efficient and accurate. This paper proposes a novel approach for this task, where NetFlow related data is correlated and a host dependency model is leveraged for advanced data mining purposes. We extend the popular linkage analysis algorithm PageRank with an additional clustering process in order to efficiently detect stealthy botnets using peer-to-peer communication infrastructures and not exhibiting large volumes of traffic. The key conceptual component in our approach is to analyze communication behavioral patterns and to infer potential botnet activities.
Fichier principal
Vignette du fichier
networking11CR.pdf (397.46 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00613597 , version 1 (05-08-2011)

Licence

Paternité

Identifiants

Citer

Jérôme François, Shaonan Wang, Radu State, Thomas Engel. BotTrack: Tracking Botnets Using NetFlow and PageRank. 10th IFIP Networking Conference (NETWORKING), May 2011, Valencia, Spain. pp.1-14, ⟨10.1007/978-3-642-20757-0_1⟩. ⟨inria-00613597⟩
461 Consultations
2354 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More