The heisenbot uncertainty problem: challenges in separating bots from chaff

  • Authors:
  • Chris Kanich;Kirill Levchenko;Brandon Enright;Geoffrey M. Voelker;Stefan Savage

  • Affiliations:
  • University of California, San Diego;University of California, San Diego;University of California, San Diego;University of California, San Diego;University of California, San Diego

  • Venue:
  • LEET'08 Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we highlight a number of challenges that arise in using crawling to measure the size, topology, and dynamism of distributed botnets. These challenges include traffic due to unrelated applications, address aliasing, and other active participants on the network such as poisoners. Based upon experience developing a crawler for the Storm botnet, we describe each of the issues we encountered in practice, our approach for managing the underlying ambiguity, and the kind of errors we believe it introduces into our estimates.