Jae-Seo Lee, Hyuncheol Jeong, Jun-Hyung Park, Minsoo Kim, Bongnam Noh
{"title":"基于周期可重复性的恶意http僵尸网络活动分析","authors":"Jae-Seo Lee, Hyuncheol Jeong, Jun-Hyung Park, Minsoo Kim, Bongnam Noh","doi":"10.1109/SECTECH.2008.52","DOIUrl":null,"url":null,"abstract":"The malicious botnets are evaluated as the serious threat of the Internet society in future. As the botnets are more clever and artful, the detection of botnets is not easy. Recently malicious botnets evolve into HTTP botnets out of typical IRC botnets and it is difficult to response effectively with existing methods which are using DNS traffic. In this paper, we show the relations of HTTP clients to HTTP servers, and propose the method to search malicious HTTP botnets by using degree of periodic repeatability.","PeriodicalId":377461,"journal":{"name":"2008 International Conference on Security Technology","volume":"51 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-12-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"70","resultStr":"{\"title\":\"The Activity Analysis of Malicious HTTP-Based Botnets Using Degree of Periodic Repeatability\",\"authors\":\"Jae-Seo Lee, Hyuncheol Jeong, Jun-Hyung Park, Minsoo Kim, Bongnam Noh\",\"doi\":\"10.1109/SECTECH.2008.52\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The malicious botnets are evaluated as the serious threat of the Internet society in future. As the botnets are more clever and artful, the detection of botnets is not easy. Recently malicious botnets evolve into HTTP botnets out of typical IRC botnets and it is difficult to response effectively with existing methods which are using DNS traffic. In this paper, we show the relations of HTTP clients to HTTP servers, and propose the method to search malicious HTTP botnets by using degree of periodic repeatability.\",\"PeriodicalId\":377461,\"journal\":{\"name\":\"2008 International Conference on Security Technology\",\"volume\":\"51 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2008-12-13\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"70\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2008 International Conference on Security Technology\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SECTECH.2008.52\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 International Conference on Security Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SECTECH.2008.52","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
The Activity Analysis of Malicious HTTP-Based Botnets Using Degree of Periodic Repeatability
The malicious botnets are evaluated as the serious threat of the Internet society in future. As the botnets are more clever and artful, the detection of botnets is not easy. Recently malicious botnets evolve into HTTP botnets out of typical IRC botnets and it is difficult to response effectively with existing methods which are using DNS traffic. In this paper, we show the relations of HTTP clients to HTTP servers, and propose the method to search malicious HTTP botnets by using degree of periodic repeatability.