Traceback framework against botmaster by sharing network communication pattern information

Seiichiro Mizoguchi, Keisuke Takemori, Yutaka Miyake, Yoshiaki Hori, Kouichi Sakurai

Research output: Chapter in Book/Report/Conference proceedingConference contribution

7 Citations (Scopus)

Abstract

In order to exterminate a botnet, we have to trace a botnet and arrest its botmaster. In this paper, we make a model of communication pattern of a C&C server that sends/receives packets to/from the botmaster. Then we discuss how botmaster trace back can be achieved. We describe which communication patterns we should focus on to find the botmaster or upper C&C servers. Furthermore, we propose a framework for botmaster trace back. In this framework, owners of servers which become to C&C server will collaborate and share the communication patterns for trace back. To do this, we propose the information sharing using communication pattern monitoring tools with the servers.

Original languageEnglish
Title of host publicationProceedings - 2011 5th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing, IMIS 2011
Pages639-644
Number of pages6
DOIs
Publication statusPublished - Sept 8 2011
Event2011 5th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing, IMIS 2011 - Seoul, Korea, Republic of
Duration: Jun 30 2011Jul 2 2011

Publication series

NameProceedings - 2011 5th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing, IMIS 2011

Other

Other2011 5th International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing, IMIS 2011
Country/TerritoryKorea, Republic of
CitySeoul
Period6/30/117/2/11

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications
  • Computer Science Applications

Fingerprint

Dive into the research topics of 'Traceback framework against botmaster by sharing network communication pattern information'. Together they form a unique fingerprint.

Cite this