Visible to the public A Botnet Detecting Infrastructure Using a Beneficial Botnet

TitleA Botnet Detecting Infrastructure Using a Beneficial Botnet
Publication TypeConference Paper
Year of Publication2018
AuthorsYamanoue, Takashi
Conference NameProceedings of the 2018 ACM on SIGUCCS Annual Conference
PublisherACM
ISBN Number978-1-4503-5582-7
KeywordsBot, botnets, Collaboration, compositionality, Metrics, pubcrawl, resilience, Resiliency, security
Abstract

A beneficial botnet, which tries to cope with technology of malicious botnets such as peer to peer (P2P) networking and Domain Generation Algorithm (DGA), is discussed. In order to cope with such botnets' technology, we are developing a beneficial botnet as an anti-bot measure, using our previous beneficial bot. The beneficial botnet is a group of beneficial bots. The peer to peer (P2P) communication of malicious botnet is hard to detect by a single Intrusion Detection System (IDS). Our beneficial botnet has the ability to detect P2P communication, using collaboration of our beneficial bots. The beneficial bot could detect communication of the pseudo botnet which mimics malicious botnet communication. Our beneficial botnet may also detect communication using DGA. Furthermore, our beneficial botnet has ability to cope with new technology of new botnets, because our beneficial botnet has the ability to evolve, as same as malicious botnets.

URLhttps://dl.acm.org/citation.cfm?doid=3235715.3235728
DOI10.1145/3235715.3235728
Citation Keyyamanoue_botnet_2018