Visible to the public Frequency Domain Analysis of Large-Scale Proxy Logs for Botnet Traffic Detection

TitleFrequency Domain Analysis of Large-Scale Proxy Logs for Botnet Traffic Detection
Publication TypeConference Paper
Year of Publication2016
AuthorsBottazzi, Giovanni, Italiano, Giuseppe F., Rutigliano, Giuseppe G.
Conference NameProceedings of the 9th International Conference on Security of Information and Networks
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4764-8
KeywordsBotnet, botnets, frequency domain, Human Behavior, logs, Metrics, mining, proxy, pubcrawl, Resiliency, Scalability
Abstract

Botnets have become one of the most significant cyber threats over the last decade. The diffusion of the "Internet of Things" and its for-profit exploitation, contributed to botnets spread and sophistication, thus providing real, efficient and profitable criminal cyber-services. Recent research on botnet detection focuses on traffic pattern-based detection, and on analyzing the network traffic generated by the infected hosts, in order to find behavioral patterns independent from the specific payloads, architectures and protocols. In this paper we address the periodic behavioral patterns of infected hosts communicating with their Command-and-Control servers. The main novelty introduced is related to the traffic analysis in the frequency domain without using the well-known Fast Fourier Transform. Moreover, the mentioned analysis is performed through the exploitation of the proxy logs, easily deployable on almost every real-world scenario, from enterprise networks to mobile devices.

URLhttp://doi.acm.org/10.1145/2947626.2947634
DOI10.1145/2947626.2947634
Citation Keybottazzi_frequency_2016