Botnet Command Detection using Virtual Honeynet

Jaswinder Singh Bhatia, Sehgal, Sanjeev Kumar · International Journal of Network Security & Its Applications · 2011

Internet attacks are growing with time, threats are increasing to disable infrastructure to those that also target peoples and organization, these increasing large attacks, and the new class of attacks directly targets the large businesses and governments around the world.At the centre of many of these attacks is a large pool of compromised computers which are called zombies commonly controlled by the attackers by using some common channels?Attackers use these zombies as anonymous proxies to hide their real identities and amplify their attacks.A botnet is a network of compromised machines that can be remotely controlled by an attacker.With the view of affect made by the botnet, we propose an approach using Virtual Honeynet data collection mechanisms to detect IRC and HTTP based botnet Command signatures.We have evaluated our approach using real world network traces.

Read the paper · More papers on PaperTik