A Taxonomy of Botnet Structures (2007)
Cached
Download Links
- [www-static.cc.gatech.edu]
- [faculty.cse.tamu.edu]
- [faculty.cs.tamu.edu]
- [www.acsac.org]
- DBLP
Other Repositories/Bibliography
| Venue: | In Proc. of the 23 Annual Computer Security Applications Conference (ACSAC'07 |
| Citations: | 29 - 3 self |
BibTeX
@INPROCEEDINGS{Dagon07ataxonomy,
author = {David Dagon and Guofei Gu and Christopher P. Lee and Wenke Lee},
title = {A Taxonomy of Botnet Structures},
booktitle = {In Proc. of the 23 Annual Computer Security Applications Conference (ACSAC'07},
year = {2007}
}
OpenURL
Abstract
We propose a taxonomy of botnet structures, based on their utility to the botmaster. We propose key metrics to measure their utility for various activities (e.g., spam, ddos). Using the performance metrics, we consider the ability of different response techniques to degrade or disrupt botnets. In particular, our models show that for scale free botnets, targeted responses are particularly effective. Further, botmasters ’ efforts to improve the robustness of scale free networks comes at a cost of diminished transitivity. Botmasters do not appear to have any structural solutions to this problem in scale free networks. We also show that random graph botnets (e.g., those using P2P formations) are highly resistant to both random and targeted responses. We evaluate the impact of responses on different topologies using simulation. We also perform some novel measurements of a P2P network to demonstrate the utility of our proposed metrics. Our analysis shows how botnets may be classified according to structure, and given rank or priority using our proposed metrics. This may help direct responses, and suggests which general remediation strategies are more likely to succeed. 1







