TY - GEN
T1 - An enhanced model for network flow based botnet detection
AU - Wijesinghe, Udaya
AU - Tupakula, Udaya
AU - Varadharajan, Vijay
PY - 2015
Y1 - 2015
N2 - The botnet is a group of hijacked computers, which are employed under command and control mechanism administered by a botmaster. Botnet evolved from IRC based centralized botnet to employing common protocols such as HTTP with decentralized architectures and then peer-to-peer designs. As Botnets have become more sophisticated, the need for advanced techniques and research against botnets has grown. In this paper, we propose techniques to detect botnets by analysing network traffic flows. We developed templates for capturing traffic flows with more relevant attributes for botnet detection. Also we make use of the IPFIX standard for the specification of the templates. Hence our techniques can be used to detect different bot families with lesser overheads and are vendor neutral.
AB - The botnet is a group of hijacked computers, which are employed under command and control mechanism administered by a botmaster. Botnet evolved from IRC based centralized botnet to employing common protocols such as HTTP with decentralized architectures and then peer-to-peer designs. As Botnets have become more sophisticated, the need for advanced techniques and research against botnets has grown. In this paper, we propose techniques to detect botnets by analysing network traffic flows. We developed templates for capturing traffic flows with more relevant attributes for botnet detection. Also we make use of the IPFIX standard for the specification of the templates. Hence our techniques can be used to detect different bot families with lesser overheads and are vendor neutral.
UR - http://www.scopus.com/inward/record.url?scp=84943169802&partnerID=8YFLogxK
M3 - Conference proceeding contribution
AN - SCOPUS:84943169802
SN - 9781921770418
VL - 159
T3 - Conferences in Research and Practice in Information Technology
SP - 101
EP - 110
BT - Proceedings of the 38th Australasian Computer Science Conference, ACSC 2015
A2 - Parry, David
PB - Australian Computer Society
CY - Sydney
T2 - Proceedings of the 38th Australasian Computer Science Conference, ACSC 2015
Y2 - 27 January 2015 through 30 January 2015
ER -