作者: Peter Wurzinger , Leyla Bilge , Thorsten Holz , Jan Goebel , Christopher Kruegel
DOI: 10.1007/978-3-642-04444-1_15
关键词:
摘要: A botnet is a network of compromised hosts that under the control single, malicious entity, often called botmaster. We present system aims to detect bots, independent any prior information about command and channels or propagation vectors, without requiring multiple infections for correlation. Our relies on detection models target characteristic fact every bot receives commands from botmaster which it responds in specific way. These are generated automatically traffic traces recorded actual instances. have implemented proposed approach demonstrate can extract effective variety different families. precise describing activity bots raise very few false positives.