Detecting Command and Control Traffic Using Botnet Correlator Module
Justin David Pineda, Japhet Eliel Marcos, Ronald Christianne David, Allan Dave Perez · 2015
The proliferation of malicious Command and Control (C&C) servers or botnets is a very big security issue in the Internet today. Triggering malware can be found in most known, popular and visited websites. Any user who is tricked in clicking something interesting (usually an advertisement) is redirected to a malicious website or unknowingly forced to install a malware that makes them a victim (also known as zombie). When a lot of users have been victimized, malware is stored in their computers in stealth mode. When thousands or millions of computers are infected, the leader can order all infected machines to do something malicious like attacking servers to cause Distributed Denial of Service (DDOS) and other attacks on confidentiality. Only in 2013, the FBI discovered millions of machines were infected by a botnet called Citadel. The agency was able to shutdown the server leaving the victims still infected. Anti-virus and firewall solutions are defenseless in this type of attacks because botnets cannot be prevented using rule-based and signature-based solutions. The Botnet Correlator Module (BCM) is a mobile and powerful tool used to determine presence of active C&C activities in a Local Area Network (LAN) topology. It is capable of reading the most updated C&C knowledgebase from reputable sources and correlating it with Intrusion Detection System (IDS) rules as a detective control. The module loads the C&C information to the firewall as primary preventive control and consolidates traffic for further analysis and incident response.