Inimitable Approach to Detect & Quarantine Botnet Malware Infections in Network

Vikas Maurya, Swati R. Chaudhari, Deepak Kumar Sirohi, Shailendra Singh Tomar, Alpana Rajan, Anil Rawat · 2021 2nd International Conference on Secure Cyber Computing and Communications (ICSCCC) · 2021

Internet connected organizational networks are susceptible to malware attacks. Best of the existing anti malware solutions are known to detect only 80% of the malwares. Latest heuristic algorithms based antimalware solutions can also fail at times in resource constrained environments. Thus organizations have to formulate additional strategies to tackle malware attacks which escape detection by standard end point security systems. Special categories of malware called botnets are the most prominent and dangerous forms, which can cause large scale damage if not quarantined timely. These days, organizations mostly use proxy servers to access the Internet, thus traces of botnets using HTTP based communication channels can be extracted from proxy logs. We experimented with the Squid proxy log analysis techniques for detection of such botnets and have developed a system which provides potential solution to quarantine malware infected PCs in an organization. In this paper, we present the design, development and analysis of complete system. The system incorporates necessary functions to provide complete life cycle management of such PCs, starting from isolation to reinstatement in the production network. The system has been implemented in our organization having 2500 active users and two squid proxy servers. It has been observed that CPU utilization on the proxy servers is reduced by about 20% and the size of access log files by about 25%, which is a big gain for organizations with large number of users.

Read the paper · More papers on PaperTik