Skip to main navigation Skip to search Skip to main content

A survey on latest botnet attack and defense

Lei Zhang*, Shui Yu, Di Wu, Paul Watters

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

A botnet is a group of compromised computers, which are remotely controlled by hackers to launch various network attacks, such as DDoS attack and information phishing. Botnet has become a popular and productive tool behind many cyber attacks. Recently, the owners of some botnets, such as storm worm, torpig and conflicker, are employing fluxing techniques to evade detection. Therefore, the understanding of their fluxing tricks is critical to the success of defending from botnet attacks. Motivated by this, we survey the latest botnet attacks and defenses in this paper. We begin with introducing the principles of fast fluxing (FF) and domain fluxing (DF), and explain how these techniques were employed by botnet owners to fly under the radar. Furthermore, we investigate the state-of-art research on fluxing detection. We also compare and evaluate those fluxing detection methods by multiple criteria. Finally, we discuss future directions on fighting against botnet based attacks.

Original languageEnglish
Title of host publicationProceedings of the 10th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom 2011), 8th IEEE International Conference on Embedded Software and Systems (ICESS 2011), and 6th International Conference on Frontier of Computer Science and Technology (FCST 2011)
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages53-60
Number of pages8
ISBN (Print)9780769546001
DOIs
Publication statusPublished - 2011
Externally publishedYes
Event10th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom 2011), 8th IEEE International Conference on Embedded Software and Systems (ICESS 2011), 6th International Conference on Frontier of Computer Science and Technology (FCST 2011) - Changsha, China
Duration: 16 Nov 201118 Nov 2011

Other

Other10th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom 2011), 8th IEEE International Conference on Embedded Software and Systems (ICESS 2011), 6th International Conference on Frontier of Computer Science and Technology (FCST 2011)
Country/TerritoryChina
CityChangsha
Period16/11/1118/11/11

Keywords

  • Botnet
  • Domain Fluxing
  • Fast Fluxing
  • Survey

Fingerprint

Dive into the research topics of 'A survey on latest botnet attack and defense'. Together they form a unique fingerprint.

Cite this