articleAug 6, 2007Closed access

BotHunter: detecting malware infection through IDS-driven dialog correlation

Georgia Institute of Technology · SRI International

Abstract

We present a new kind of network perimeter monitoring strategy, which focuses on recognizing the infection and coordination dialog that occurs during a successful malware infection. BotHunter is an application designed to track the two-way communication flows between internal assets and external entities, developing an evidence trail of data exchanges that match a state-based infection sequence model. BotHunter consists of a correlation engine that is driven by three malware-focused network packet sensors, each charged with detecting specific stages of the malware infection process, including inbound scanning, exploit usage, egg downloading, outbound bot coordination dialog, and outbound attack propagation.…

Citation impact

692
total citations
FWCI
54.87
Percentile
100%
References
41
Citations per year

Authors

5

Topics & keywords

Keywords
  • Malware
  • Dialog box
  • Computer science
  • Exploit
  • Network packet
  • Intrusion detection system
  • The Internet
  • Botnet
UN Sustainable Development Goals
  • Responsible consumption and production
No related works found for this paper.