Botnet Fingerprint Using Bro-IDS
Esraa Alshammari, Alaa H. Alhammami, Ali Hadi · Zenodo (CERN European Organization for Nuclear Research) · 2020
Abstract— Botnets or robot networks are one of the most serious and widespread attacks in the network’s era. This attack is used to enforce the control of the computers by injecting a small code into the computer to become one of the bots in the robot networks. Then the new bot will be linked with the supervisor or botmaster to get the instruction and commands that need to perform. Command and Control server (C&C) is the botmaster which sends the tasks to their connected bots. The motivations of using and launching such attacks are diverse from DDoS to spam, attacking IRC chat, spreading new malware, and gathering information… etc. Many of the botnet detection technique is based on the Intrusion Detection System (IDS) or Intrusion Prevention System (IPS), while the sophisticated technologies of the attackers are increasing to evade such system. Thus, the need for robust and advanced techniques is necessary due to the growth of the botnet attacks. In this paper, the main types and architecture for the botnet attacks will be presented. Additionally, the detection technique will be presented using Bro Monitoring tools in order to analyze in depth the network traffic, then detect the abnormal or malicious traffic that comes from the C&C server. This research considered as a step forward to detecting the botnet attack. Keywords— Attacks, Botnet; Bro; Detection Techniques; Malware; Traffic Analysis