Characterisation of the Kelihos.B Botnet - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2014

Characterisation of the Kelihos.B Botnet

Max Kerkers
  • Fonction : Auteur
  • PersonId : 994061
José Jair Santanna
  • Fonction : Auteur
  • PersonId : 994059
Anna Sperotto
  • Fonction : Auteur
  • PersonId : 994060

Résumé

Botnets are organized networks of infected computers that are used for malicious purposes. An example is Kelihos.B, a botnet of the Kelihos family used primarily for mining bitcoins, sending spam and stealing bitcoin wallets. A large part of the Kelihos.B botnet was sinkholed in early 2012 and since then bots are sending requests to controlled servers. In this paper, we analyze and characterize the behavior of Kelihos. B. Our analysis is based on the log file of the bot request logged at the sinkhole from March 2012 to early November 2013. We investigate both the overall characteristics of the botnets, as well as on its evolution over time since the time of the sinkholing. Our results indicate that, although this trend is decreasing, there are possibly still newly infected bots even more than a year from the original sinkholing.
Fichier principal
Vignette du fichier
978-3-662-43862-6_11_Chapter.pdf (1.3 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01401294 , version 1 (23-11-2016)

Licence

Paternité

Identifiants

Citer

Max Kerkers, José Jair Santanna, Anna Sperotto. Characterisation of the Kelihos.B Botnet. 8th IFIP International Conference on Autonomous Infrastructure, Management and Security (AIMS), Jun 2014, Brno, Czech Republic. pp.79-91, ⟨10.1007/978-3-662-43862-6_11⟩. ⟨hal-01401294⟩
76 Consultations
122 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More