6th International Symposium on Telecommunications (IST) 2012
DOI: 10.1109/istel.2012.6483133
|View full text |Cite
|
Sign up to set email alerts
|

Real-time Botnet command and control characterization at the host level

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
9
0

Year Published

2013
2013
2020
2020

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 9 publications
(9 citation statements)
references
References 15 publications
0
9
0
Order By: Relevance
“…In this case, we need a host-based detection to eliminate the bot program from the host. ere are various researches in host-based detection techniques [9][10][11]. Huang [10] proposes an effective bot host detection solution based on network failure tracking in a host during short period.…”
Section: Botnet Detection At the Host Sidementioning
confidence: 99%
“…In this case, we need a host-based detection to eliminate the bot program from the host. ere are various researches in host-based detection techniques [9][10][11]. Huang [10] proposes an effective bot host detection solution based on network failure tracking in a host during short period.…”
Section: Botnet Detection At the Host Sidementioning
confidence: 99%
“…They suggest that the false positives (caused mainly by software updates) can be minimised using whitelisting. Etemad & Vahdani (2012) take a similar approach for centralised botnet detection. Like Wang et al (2010), they identify C&C traffic by the presence of periodic HTTP messages.…”
Section: Identification Of Control Trafficmentioning
confidence: 99%
“…Bot Traffic: Repetitive HTTP requests generated at regular intervals. Features: Degree of periodic repeatability (Etemad & Vahdani, 2012), periodic factor (Eslahi et al, 2015), HTTP messages range of absolute frequencies (Eslahi et al, 2015), HTTP messages time sequence (Eslahi et al, 2015), HTTP request density (Cai & Zou, 2012), HTTP request periodicity (Eslahi et al, 2013) Bots communicating with C&Cs over HTTP need to poll them continuously to receive updates. To achieve this, they will repeatedly generate similar HTTP requests to the server at regular intervals.…”
Section: Application Layer/httpmentioning
confidence: 99%
See 2 more Smart Citations