Skip to main content
QUICK REVIEW

[論文レビュー] Multi-phase IRC Botnet and Botnet Behavior Detection Model

Aymen Hasan Rashid Al Awadi, Bahari Belaton|arXiv (Cornell University)|Jan 13, 2015
Network Security and Intrusion Detection参考文献 3被引用数 12
ひとこと要約

本論文では、C&C応答メッセージと悪意のある行動を分析することで、通信プロトコルに依存せず、感染したホストを特定し、悪意のあるトラフィックをフィルタリングし、ボットネット活動を検出する、マルチフェーズのIDSベースの検出モデルを提案する。実際のネットワークトレースを用いた評価において、固定時間窓や特定のボットシグネチャに依存しないことで、低誤検出率のもとでほぼ完璧な検出性能を達成し、従来の手法を上回った。

ABSTRACT

Botnets are considered one of the most dangerous and serious security threats facing the networks and the Internet. Comparing with the other security threats, botnet members have the ability to be directed and controlled via C&C messages from the botmaster over common protocols such as IRC and HTTP, or even over covert and unknown applications. As for IRC botnets, general security instances like firewalls and IDSes do not provide by themselves a viable solution to prevent them completely. These devices could not differentiate well between the legitimate and malicious traffic of the IRC protocol. So, this paper is proposing an IDS-based and multi-phase IRC botnet and botnet behavior detection model based on C&C responses messages and malicious behaviors of the IRC bots inside the network environment. The proposed model has been evaluated on five network traffic traces from two different network environments (Virtual network and DARPA 2000 Windows NT Attack Data Set). The results show that the proposed model could detect all the infected IRC botnet member(s), state their current status of attack, filter their malicious IRC messages, pass the other normal IRC messages and detect the botnet behavior regardless of the botnet communication protocol with very low false positive rate. The proposed model has been compared with some of the existing and well-known approaches, including BotHunter, BotSniffer and Rishi regarding botnet characteristics taken in each approach. The comparison showed that the proposed model has made a progress on the comparative models by not to rely on a certain time window or specific bot signatures.

研究の動機と目的

  • ファイアウォールやIDSといった従来のセキュリティデバイスが、正当なトラフィックと悪意あるIRCトラフィックを区別できないという限界を解決すること。
  • 事前に定義された時間窓やボットシグネチャに依存せずに、IRCボットネットのメンバーとその攻撃状態を特定する検出モデルを開発すること。
  • 通常のIRC通信が妨げられないように、悪意あるIRCメッセージをフィルタリングすること。
  • ボットネットが使用する下位の通信プロトコルにかかわらず、ボットネット行動を検出できること。
  • BotHunter、BotSniffer、Rishiといった既存の手法と比較して、検出精度を向上させ、誤検出率を低減すること。

提案手法

  • 本モデルは、IRCボットからのC&C応答メッセージを分析するマルチフェーズ検出アプローチを採用する。
  • コマンドアンドコントロールシグナルを示すパターンを特定することで、IRCトラフィックを悪意ある行動の兆候として分類する。
  • ボットネット運用に関連する行動的異常、例えばコマンド実行やデータ漏洩のパターンを監視することで、ネットワークトラフィックをモニタリングする。
  • 仮想ネットワークとDARPA 2000 Windows NTアタックデータセットの両方からのネットワークトラフィックトレースを活用する。
  • 検出ロジックはプロトコルに依存しない設計となっており、ボットネットの下位通信プロトコルに関わらず、ボットネット活動を同定可能である。
  • 悪意あると良性のIRCトラフィックを区別するために、ルールベースおよび行動ベースの分類エンジンを採用する。

実験結果

リサーチクエスチョン

  • RQ1C&C応答メッセージのみを用いて、IRCボットネットのメンバーとその現在の攻撃状態を特定できるか?
  • RQ2固定時間窓や特定のシグネチャに依存せずに、悪意あるIRCトラフィックと正当なIRCトラフィックをどれほど効果的に区別できるか?
  • RQ3異なる通信プロトコルを用いるボットネットに対し、どの程度の範囲でボットネット行動を検出できるか?
  • RQ4実世界のネットワークトレースに適用した際の本モデルの誤検出率はどの程度か?
  • RQ5BotHunter、BotSniffer、Rishiといった既存のボットネット検出システムと比較して、本モデルの性能はいかがなものか?

主な発見

  • 評価されたネットワークトレースにおいて、提案モデルはすべての感染したIRCボットネットメンバーを正常に検出できた。
  • 本モデルは、各ボットの攻撃フェーズの現在の状態を正確に報告でき、リアルタイムでの状況把握を可能にした。
  • 悪意あるIRCメッセージは効果的にフィルタリングされたが、通常のIRC通信は遮断なく通過した。
  • 本モデルは非常に低い誤検出率を示しており、悪意ある行動と良性の行動を高精度に区別できることを示した。
  • 特定の時間窓やシグネチャベースの検出に依存しないため、BotHunter、BotSniffer、Rishiといった既存手法を上回る性能を発揮した。
  • ボットネットが使用する下位通信プロトコルにかかわらず、検出能力が安定しており、プロトコルに依存しない行動検出の有効性が確認された。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。