IRC Traffic Analysis for Botnet Detection

  • Authors:
  • Claudio Mazzariello

  • Affiliations:
  • -

  • Venue:
  • IAS '08 Proceedings of the 2008 The Fourth International Conference on Information Assurance and Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Networked hosts' vulnerabilities pose some serious threats to the operation of computer networks. Modern attacks are increasingly complex, and exploit many strategies in order to perform their intended malicious tasks. Attackers have developed the ability of controlling large sets of infected hosts, characterized by complex executable command sets, each taking part incooperative and coordinated attacks. There are many ways to perform control onan \emph{army} of possibly unaware infected hosts, and an example of such techniques is discussed in this paper. We will address the problem of detecting \emph{botnets}, by introducing a network traffic analysis architecture, and describing a behavioral model, for a specific class of network users, capable of identifying \emph{botnet}-related activities.