Skip to main content
QUICK REVIEW

[논문 리뷰] Multi-phase IRC Botnet and Botnet Behavior Detection Model

Aymen Hasan Rashid Al Awadi, Bahari Belaton|arXiv (Cornell University)|2015. 01. 13.
Network Security and Intrusion Detection참고 문헌 3인용 수 12
한 줄 요약

이 논문은 C&C 응답 메시지와 악성 행동을 분석하여, 통신 프로토콜에 관계없이 감염된 호스트를 식별하고 악성 트래픽을 걸러내며 봇넷 활동을 탐지하는 다단계 IDS 기반 감지 모델을 제안한다. 실제 네트워크 트레이스에서 평가한 결과, 고정된 시간 창이나 특정 봇 시그니처에 의존하지 않음으로써 기존 방법보다 뛰어난 성능을 보이며, 거의 완벽한 탐지율과 낮은 위양성 비율을 달성하였다.

ABSTRACT

Botnets are considered one of the most dangerous and serious security threats facing the networks and the Internet. Comparing with the other security threats, botnet members have the ability to be directed and controlled via C&C messages from the botmaster over common protocols such as IRC and HTTP, or even over covert and unknown applications. As for IRC botnets, general security instances like firewalls and IDSes do not provide by themselves a viable solution to prevent them completely. These devices could not differentiate well between the legitimate and malicious traffic of the IRC protocol. So, this paper is proposing an IDS-based and multi-phase IRC botnet and botnet behavior detection model based on C&C responses messages and malicious behaviors of the IRC bots inside the network environment. The proposed model has been evaluated on five network traffic traces from two different network environments (Virtual network and DARPA 2000 Windows NT Attack Data Set). The results show that the proposed model could detect all the infected IRC botnet member(s), state their current status of attack, filter their malicious IRC messages, pass the other normal IRC messages and detect the botnet behavior regardless of the botnet communication protocol with very low false positive rate. The proposed model has been compared with some of the existing and well-known approaches, including BotHunter, BotSniffer and Rishi regarding botnet characteristics taken in each approach. The comparison showed that the proposed model has made a progress on the comparative models by not to rely on a certain time window or specific bot signatures.

연구 동기 및 목표

  • 기존 방화벽 및 IDS와 같은 전통적 보안 장치가 악성 IRC 트래픽과 정상 트래픽을 구분하는 데 한계가 있음을 해결하기 위해.
  • 사전 정의된 시간 창이나 봇 시그니처에 의존하지 않고 IRC 봇넷 멤버와 그들의 공격 상태를 식별하는 감지 모델을 개발하기 위해.
  • 정상 IRC 통신이 방해받지 않도록 하면서도 악성 IRC 메시지를 걸러내기 위해.
  • 봇넷이 사용하는 기반 통신 프로토콜에 관계없이 봇넷 행동을 탐지하기 위해.
  • BotHunter, BotSniffer, Rishi와 같은 기존 접근 방식에 비해 탐지 정확도를 향상시키고 위양성 비율을 낮추기 위해.

제안 방법

  • 모델은 IRC 봇의 C&C 응답 메시지를 분석하는 다단계 감지 접근 방식을 사용한다.
  • 명령 및 제어 신호와 같은 악성 행동의 징후를 식별함으로써 IRC 트래픽을 분류한다.
  • 명령 실행 및 데이터 유출 패턴과 같은 봇넷 운영과 관련된 행동 이상 징후를 네트워크 트래픽에서 모니터링한다.
  • 가상 네트워크와 DARPA 2000 Windows NT 공격 데이터 세트 두 환경의 네트워크 트래픽 트레이스를 활용한다.
  • 감지 논리는 프로토콜에 종속되지 않도록 설계되어, 기반 통신 프로토콜에 관계없이 봇넷 활동을 식별할 수 있다.
  • 규칙 기반 및 행동 기반 분류 엔진을 활용하여 정상 및 악성 IRC 트래픽을 구분한다.

실험 결과

연구 질문

  • RQ1C&C 응답 메시지만을 사용하여 감지 모델이 IRC 봇넷 멤버와 현재 공격 단계를 식별할 수 있는가?
  • RQ2고정된 시간 창이나 특정 시그니처에 의존하지 않고, 모델이 악성 IRC 트래픽과 정상 IRC 트래픽을 얼마나 효과적으로 구분할 수 있는가?
  • RQ3모델이 다양한 통신 프로토콜을 통해 봇넷 행동을 어느 정도 탐지할 수 있는가?
  • RQ4모델이 실제 웹 트래픽 트레이스에 적용되었을 때의 위양성 비율은 얼마인가?
  • RQ5BotHunter, BotSniffer, Rishi와 같은 기존 봇넷 감지 시스템과 비교해 성능 면에서 모델은 어떻게 성과를 내는가?

주요 결과

  • 평가된 네트워크 트레이스에서 제안된 모델은 모든 감염된 IRC 봇넷 멤버를 성공적으로 탐지하였다.
  • 모델은 각 봇의 공격 단계 현재 상태를 정확히 보고하여 실시간 상황 인식이 가능했다.
  • 정상 IRC 트래픽이 방해받지 않도록 하면서도 악성 IRC 메시지를 효과적으로 걸러냈다.
  • 모델은 매우 낮은 위양성 비율을 보이며, 악성 행동와 정상 행동를 높은 정밀도로 구분함을 확인하였다.
  • 특정 시간 창이나 시그니처 기반 탐지에 의존하지 않음으로써, BotHunter, BotSniffer, Rishi와 같은 기존 접근 방식보다 뛰어난 성능을 보였다.
  • 봇넷이 사용하는 기반 통신 프로토콜에 관계없이 탐지 능력이 뛰어나 봇넷 행동 탐지의 프로토콜에 종속되지 않는 특성을 확인하였다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.