Detection of botnets before activation: an enhanced honeypot system for intentional infection and behavioral observation of malware

Citations

WEB OF SCIENCE

5
Citations

SCOPUS

8

초록

As botnets have become the primary means for cyber attacks, how to detect botnets becomes an important issue for researchers and practitioners. In this study, we introduce a system that is designed to detect botnets prior to their activation. Pre-detection of botnets becomes available with our enhanced honeypot system that allows us to intentionally infect virtual machines in honeynets. For empirical testing, we applied our system to a major Internet service provider in Korea. After running our proposed system for 12?months, it was found that nearly 40% of blacklisted botnets were pre-detected by our system before their attacks begin. We expect that our system can be used to detect command-and-control servers and to screen them out during their propagation stage before they make harmful attacks. Copyright (c) 2012 John Wiley & Sons, Ltd.

키워드

botnet detectionmalwarehoneynetsintentional infectionbehavioral analysis
제목
Detection of botnets before activation: an enhanced honeypot system for intentional infection and behavioral observation of malware
저자
Moon, Young HoonKim, EunjinHur, Suh MahnKim, Huy Kang
DOI
10.1002/sec.431
발행일
2012-10
유형
Article
저널명
Security and Communication Networks
5
10
페이지
1094 ~ 1101