Revealing Botnets Using Network Traffic Statistics
Pavel Čeleda, Radek Krejčí, Vojtěch Krmíček · 2011
This paper, based on real world malware observations, presents a state-of-the-art overview of Unix-like embedded malware. We describe botnets using network connected embedded devices (ADSL modems, WiFi routers, etc.) for illicit activities. There does not exist suitable security solution (anti-virus or anti-malware) for these devices. We propose an approach using network traffic statistics to reveal Unix-like embedded malware and its activities.