Publication Type : Journal Article
Publisher : International Journal of Electronic Security and Digital Forensics
Source : International Journal of Electronic Security and Digital Forensics, 5(3-4), 188-200
Url : https://dl.acm.org/doi/abs/10.1504/IJESDF.2013.058653
Campus : Coimbatore
School : School of Physical Sciences
Department : Mathematics
Year : 2013
Abstract : Botnet has become a prevalent platform for many malicious attacks and hence it is considered as a serious threat to internet security. A botmaster can control millions of compromised systems using command & control C&C infrastructure. At early time IRC protocol-based botnets were used by the attackers. Recently attackers have shifted their paradigm towards HTTP-based C&C server because of several advantages and in this situation, bots frequently request and download commands from web servers which are under the control of botmaster. Since web-based C&C bots try to blend into normal HTTP traffic, it is difficult to identify HTTP botnets. In this work, we propose a hidden semi-Markov model HsMM to characterise the normal network behaviour considering that most of the communications of web-based bots are based on TCP. We use TCP-based MIB variables as observed sequence and forward-backward algorithm for estimating model parameters to best account for an observed sequence. Several experiments are conducted to validate our model. The proposed system is lightweight and real time.
Cite this Research Publication : Venkatesh, G. K., Srihari, V., Veeramani, R., Karthikeyan, R. M., &Anitha, R. (2013). Http botnet detection using hidden semi-markov model with snmpmib variables. International Journal of Electronic Security and Digital Forensics, 5(3-4), 188-200