BotTracer: Execution-Based Bot-Like Malware Detection

INFORMATION SECURITY, PROCEEDINGS(2008)

引用 108|浏览0
暂无评分
摘要
Bot-like malware has posed an immense threat to computer security. Bot detection is still a challenging task since bot developers are continuously adopting advanced techniques to make bots more stealthy. A typical bot exhibits three invariant features along its onset: (1) the startup of a bot is automatic without requiring any user actions; (2) a bot must establish a command and control channel with its botmaster; and (3) a bot will perform local or remote attacks sooner or later. These invariants indicate three indispensable phases (startup, preparation, and attack) for a bot attack. In this paper, we propose BotTracer to detect these three phases with the assistance of virtual machine techniques. To validate BotTracer, we implement a prototype of BotTracer based on VMware and Windows XP Professional. The results show that BotTracer has successfully detected all the bots in the experiments without any false negatives.
更多
查看译文
关键词
remote attack,bot attack,bot detection,challenging task,execution-based bot-like malware detection,computer security,advanced technique,typical bot,bot developer,bot-like malware,windows xp professional,virtual machine,botnet
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要