Detection and Defense with the Command-and-Control Channels in the Social Network-Based BotNet

Author(s):
Message:
Abstract:
A BotNet is a collection of Bots that are run separately on infected Computers and respond to commands sent from command and control unit. Nowadays, BotNets are a major challenge in cyberspace . New species of this family of malware abuses the popular social networking sites as command and control channels. In this way, the usual protective systems such as IDS will not be able to identify and deal with BotNets, because the network traffic generated by BotNets is similar to the user traffic system. In this paper, a new method is presented to detect, intercept and deal with BotNets based social networks. In this method, BotNet detection is done based on the system resource monitoring. After tracing, the proposed method intercepts with the BotNet. This interception includes preventing from the command and control server. the proposed method can detect nearly 96% of BotNets and can caus the system to discover 100% of BotNets successfully.
Language:
Persian
Published:
Passive Defense Quarterly, Volume:8 Issue: 1, 2017
Page:
35
https://www.magiran.com/p1677052