A Large-Scale P2P Botnet Detection Framework via Topology and Traffic Co-Verification

Ziming Zhao, Zhaoxuan Li, Tingting Li, Fan Zhang · 2024

Botnets are still serious threats to infrastructure security nowadays. Recently, adversaries tend to leverage peer-to-peer (P2P) manner propagation to construct large-scale botnets since P2P-based schemes have no single points of failure. Over the past few decades, the research and industry communities have proposed a variety of solutions to detect botnets, which mainly involve communication topology identification and network traffic analysis. Yet, coping with the large-scale P2P botnets, the former suffer topology indistinguishability, and the latter struggles under massive background traffic. In this paper, we present TNT, a large-scale P2P botnet detection framework via communication topology and network traffic. As its core, TNT is powered by three tightly-coupled components: (i) tScouter is responsible for profiling the communication topology; (ii) tCommander plans the strategy for node inspection; and (iii) tPatroller investigates the traffic of the corresponding node. Taken together, TNT advances the trade-off between detection accuracy (enhance topology-based results via traffic analysis) and overhead (only check part of node traffic according to the planning). Based on 42 groups of combinations involving 6 types of botnets and 7 legitimate P2P traffic, we perform extensive evaluation and demonstrate that TNT realizes outstanding detection performance, e.g., after checking ~20K nodes, achieve ~99.9% accuracy for a communication graph (including >140K nodes).

Read the paper · More papers on PaperTik