AppBot: a novel P2P botnet architecture resistant to graph-based tracking

被引:0
|
作者
Yin, Tao [1 ]
Zhang, Yongzheng [1 ]
Li, Jia [2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Natl Comp Network Emergency Response Tech Team, Coordinat Ctr China, Beijing, Peoples R China
基金
中国国家自然科学基金; 国家高技术研究发展计划(863计划);
关键词
D O I
10.1109/TrustCom.2016.116
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
P2P architectures have been widely adopted by botnets for their high robustness. As the complex Command and Control (C&C) mechanism inevitably leads to too many interactions among bots, the P2P topology characteristics of traditional P2P botnet architectures is likely to be exposed to defenders, which makes them vulnerable to graph-based tracking. Inspired by the infeasibility of monitoring the global Internet and the diffculty of IP traceback problem, we propose a novel P2P botnet architecture, called AppBot, which is resistant to graph-based tracking. The key idea behind our proposal is two-folds: i) interactions are strictly restricted across different domains, and ii) IP spoofing is used to hide the origins of bots' interactions. Based on the real botnet distribution and background traffic of mainland China, we provide a realistic scenario for our experiments. In order to systematically evaluate AppBot, we compare it with two other typical P2P botnet architectures (HppBot and KppBot) in terms of the performance against one of the best graph-based tracking methods. We repeat our experiments by varying the botnet distribution (Gafgyt distribution and IMDDOS distribution). Each experiment is conducted on the mixture of synthetic botnet traffic and real background traffic of Xinjiang domain and Hainan domain, respectively. Experimental results show that AppBot shows a significantly high anti-tracking performance over all experimental settings. The average anti-tracking performances of AppBot, HppBot and KppBot are 46.88%, 20.45% and 24.28%, respectively.
引用
收藏
页码:615 / 622
页数:8
相关论文
共 50 条
  • [1] P2P Network Structure Graph Finding for P2P Botnet Detection
    Yuan, Zhi-chao
    Li, Yuan-long
    Yao, Shan
    Xia, Chun-he
    INTERNATIONAL CONFERENCE ON COMPUTER, NETWORK SECURITY AND COMMUNICATION ENGINEERING (CNSCE 2014), 2014, : 697 - 701
  • [2] P2P Botnet Detection Method Based on Graph Neural Network
    Lin H.
    Zhang Y.
    Guo N.
    Chen L.
    Gongcheng Kexue Yu Jishu/Advanced Engineering Sciences, 2022, 54 (02): : 65 - 72
  • [3] Tracking IoT P2P Botnet Loaders in the Wild
    Almazarqi, Hatem A.
    Woodyard, Mathew
    Mursch, Troy
    Pezaros, Dimitrios
    Marnerides, Angelos K.
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 5916 - 5921
  • [4] Long Term Tracking and Characterization of P2P Botnet
    Yan, Jia
    Ying, Lingyun
    Yang, Yi
    Su, Purui
    Feng, Dengguo
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 244 - 251
  • [5] Graph-based P2P Traffic Classification at the Internet Backbone
    Iliofotou, Marios
    Kim, Hyun-chul
    Faloutsos, Michalis
    Mitzenmacher, Michael
    Pappu, Prashanth
    Varghese, George
    IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS, 2009, : 37 - +
  • [6] An Efficient Botnet Detection System for P2P Botnet
    Thangapandiyan, M.
    Anand, P. M. Rubesh
    PROCEEDINGS OF THE 2016 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, SIGNAL PROCESSING AND NETWORKING (WISPNET), 2016, : 1217 - 1221
  • [7] The novel approach of P2P Botnet node-based detection and applications
    Zhao, Yu, 1600, Journal of Chemical and Pharmaceutical Research, 3/668 Malviya Nagar, Jaipur, Rajasthan, India (06):
  • [8] Botnet and P2P Botnet Detection Strategies: A Review
    Dhayal, Himanshi
    Kumar, Jitender
    PROCEEDINGS OF THE 2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION AND SIGNAL PROCESSING (ICCSP), 2018, : 1077 - 1082
  • [9] Research of Key Nodes of Botnet Based on P2P
    Gao, Jian
    Zheng, KangFeng
    Yang, YiXian
    Niu, XinXin
    COMPUTER-AIDED DESIGN, MANUFACTURING, MODELING AND SIMULATION, PTS 1-2, 2011, 88-89 : 386 - 390
  • [10] A Mobile Botnet Model Based on P2P Grid
    Simon, Marek
    Huraj, Ladislav
    Hostovecky, Marian
    CREATIVITY IN INTELLIGENT TECHNOLOGIES AND DATA SCIENCE, (CIT&DS), 2017, 754 : 604 - 615