TY - GEN
T1 - Bot detection based on traffic analysis
AU - Kugisaki, Yuji
AU - Kasahara, Yoshiaki
AU - Hori, Yoshiaki
AU - Sakurai, Kouichi
PY - 2007
Y1 - 2007
N2 - Recently, botnet becomes a social problem due to the expansion of bot infection. Ideally, all the vulnerable computers should be fortified to counteract laying malware. Accordingly, it is important to implement an information system which detects bot-infected computers and alerts them. In this paper, we focused on bots using IRC to communicate, and examined the behavior of such bots when they connected to an IRC server. We observed the actual traffic of some ports which were often used by IRC protocol. As a result, we confirmed that bots tried to reconnect to an IRC server at certain intervals when the server refused the connection from the bot. Moreover, we examined the distribution of the intervals and confirmed that the communication from other IP addresses showed similar behavior.
AB - Recently, botnet becomes a social problem due to the expansion of bot infection. Ideally, all the vulnerable computers should be fortified to counteract laying malware. Accordingly, it is important to implement an information system which detects bot-infected computers and alerts them. In this paper, we focused on bots using IRC to communicate, and examined the behavior of such bots when they connected to an IRC server. We observed the actual traffic of some ports which were often used by IRC protocol. As a result, we confirmed that bots tried to reconnect to an IRC server at certain intervals when the server refused the connection from the bot. Moreover, we examined the distribution of the intervals and confirmed that the communication from other IP addresses showed similar behavior.
UR - http://www.scopus.com/inward/record.url?scp=50249168251&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=50249168251&partnerID=8YFLogxK
U2 - 10.1109/IPC.2007.91
DO - 10.1109/IPC.2007.91
M3 - Conference contribution
AN - SCOPUS:50249168251
SN - 0769530060
SN - 9780769530062
T3 - Proceedings The 2007 International Conference on Intelligent Pervasive Computing, IPC 2007
SP - 303
EP - 306
BT - Proceedings The 2007 International Conference on Intelligent Pervasive Computing, IPC 2007
T2 - 2007 International Conference on Intelligent Pervasive Computing, IPC 2007
Y2 - 11 October 2007 through 13 October 2007
ER -