Enhanced PeerHunter: Detecting Peer-to-peer Botnets through Network-Flow Level Community Behavior Analysis

02/23/2018
by   Di Zhuang, et al.
0

Peer-to-peer (P2P) have become one of the major threats in network security for serving as the fundamental infrastructure that responsible for various cyber-crimes. More challenges are involved in the problem of detecting P2P botnets, despite a few existing works claimed to detect traditional botnets effectively. In this paper, we present Enhanced PeerHunter, a network-flow level botnet community behavior analysis based method, which is capable of detecting botnets that communicate via P2P overlay networks. Our method starts from a P2P network flow detection component. Then, it uses the natural botnet behavior "mutual contacts" as the main feature to cluster bots into communities. Finally, it uses network-flow level botnet community behavior analysis to detect potential botnet communities and further identify bot candidates. In the experimental evaluation, we propose two evasion attacks, in which we assume the adversaries (e.g., the botmasters) know our techniques in advance, and they might attempt to evade our system via making the P2P bots mimic the behavior of legitimate P2P applications. The extensive experiments' results show that Enhanced PeerHunter can achieve high detection rate with few false positives, and high robustness against the proposed mimicking legitimate P2P application attacks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/24/2022

A Reinforcement Approach for Detecting P2P Botnet Communities in Dynamic Communication Graphs

Peer-to-peer (P2P) botnets use decentralized command and control network...
research
07/31/2020

Patterns of Patient and Caregiver Mutual Support Connections in an Online Health Community

Online health communities offer the promise of support benefits to users...
research
01/27/2022

On the Anonymity of Peer-To-Peer Network Anonymity Schemes Used by Cryptocurrencies

Cryptocurrency systems can be subject to deanonymization attacks by expl...
research
08/31/2023

Learning From Peers: A Survey of Perception and Utilization of Online Peer Support Among Informal Dementia Caregivers

Informal dementia caregivers are those who care for a person living with...
research
07/17/2022

Review of Peer-to-Peer Botnets and Detection Mechanisms

Cybercrimes are becoming a bigger menace to both people and corporations...
research
10/07/2021

AS-Level BGP Community Usage Classification

BGP communities are a popular mechanism used by network operators for tr...
research
08/27/2018

Choosing How to Choose Papers

It is common to see a handful of reviewers reject a highly novel paper, ...

Please sign up or login with your details

Forgot password? Click here to reset