BotHunter: detecting malware infection through IDS-driven dialog correlation
Georgia Institute of Technology · SRI International
Abstract
We present a new kind of network perimeter monitoring strategy, which focuses on recognizing the infection and coordination dialog that occurs during a successful malware infection. BotHunter is an application designed to track the two-way communication flows between internal assets and external entities, developing an evidence trail of data exchanges that match a state-based infection sequence model. BotHunter consists of a correlation engine that is driven by three malware-focused network packet sensors, each charged with detecting specific stages of the malware infection process, including inbound scanning, exploit usage, egg downloading, outbound bot coordination dialog, and outbound attack propagation.…
Citation impact
- FWCI
- 54.87
- Percentile
- 100%
- References
- 41
Authors
5Topics & keywords
- Malware
- Dialog box
- Computer science
- Exploit
- Network packet
- Intrusion detection system
- The Internet
- Botnet
- Responsible consumption and production