作者
Jérôme François, Shaonan Wang, Radu State, Thomas Engel
发表日期
2011
研讨会论文
NETWORKING 2011: 10th International IFIP TC 6 Networking Conference, Valencia, Spain, May 9-13, 2011, Proceedings, Part I 10
页码范围
1-14
出版商
Springer Berlin Heidelberg
简介
With large scale botnets emerging as one of the major current threats, the automatic detection of botnet traffic is of high importance for service providers and large campus network monitoring. Faced with high speed network connections, detecting botnets must be efficient and accurate. This paper proposes a novel approach for this task, where NetFlow related data is correlated and a host dependency model is leveraged for advanced data mining purposes. We extend the popular linkage analysis algorithm PageRank [27] with an additional clustering process in order to efficiently detect stealthy botnets using peer-to-peer communication infrastructures and not exhibiting large volumes of traffic. The key conceptual component in our approach is to analyze communication behavioral patterns and to infer potential botnet activities.
引用总数
201120122013201420152016201720182019202020212022202344212318172211815873
学术搜索中的文章
J François, S Wang, R State, T Engel - NETWORKING 2011: 10th International IFIP TC 6 …, 2011