상세 보기
Detection of botnets before activation: an enhanced honeypot system for intentional infection and behavioral observation of malware
- Moon, Young Hoon;
- Kim, Eunjin;
- Hur, Suh Mahn;
- Kim, Huy Kang
WEB OF SCIENCE
5SCOPUS
8초록
As botnets have become the primary means for cyber attacks, how to detect botnets becomes an important issue for researchers and practitioners. In this study, we introduce a system that is designed to detect botnets prior to their activation. Pre-detection of botnets becomes available with our enhanced honeypot system that allows us to intentionally infect virtual machines in honeynets. For empirical testing, we applied our system to a major Internet service provider in Korea. After running our proposed system for 12?months, it was found that nearly 40% of blacklisted botnets were pre-detected by our system before their attacks begin. We expect that our system can be used to detect command-and-control servers and to screen them out during their propagation stage before they make harmful attacks. Copyright (c) 2012 John Wiley & Sons, Ltd.
키워드
- 제목
- Detection of botnets before activation: an enhanced honeypot system for intentional infection and behavioral observation of malware
- 저자
- Moon, Young Hoon; Kim, Eunjin; Hur, Suh Mahn; Kim, Huy Kang
- DOI
- 10.1002/sec.431
- 발행일
- 2012-10
- 유형
- Article
- 권
- 5
- 호
- 10
- 페이지
- 1094 ~ 1101