{"title":"Virtual honeypots and detection of telnet botnets","authors":"Tomáš Bajtoš, Pavol Sokol, Terézia Mézesová","doi":"10.1145/3277570.3277572","DOIUrl":null,"url":null,"abstract":"Despite recommendations to not use telnet, there is an increasing number of telnet-based botnets and a need to analyse these attacks. We deployed a network of high interaction honeypots that simulate telnet devices. From the collected data, we created a dataset that we analysed from different perspectives. In this paper, we focus on the infection phase of botnets. Based on the found signatures collected by our samples, we can divide the botnets into 9 families. We show dependencies between commands, and between commands and directories used to propagate botnets.","PeriodicalId":164597,"journal":{"name":"Proceedings of the Central European Cybersecurity Conference 2018","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-11-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the Central European Cybersecurity Conference 2018","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3277570.3277572","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7
Abstract
Despite recommendations to not use telnet, there is an increasing number of telnet-based botnets and a need to analyse these attacks. We deployed a network of high interaction honeypots that simulate telnet devices. From the collected data, we created a dataset that we analysed from different perspectives. In this paper, we focus on the infection phase of botnets. Based on the found signatures collected by our samples, we can divide the botnets into 9 families. We show dependencies between commands, and between commands and directories used to propagate botnets.