Back close

HTTP botnet detection using hidden semi-Markov model with SNMP MIB variables

Publication Type : Journal Article

Publisher : International Journal of Electronic Security and Digital Forensics

Source : International Journal of Electronic Security and Digital Forensics, 5(3-4), 188-200

Url : https://dl.acm.org/doi/abs/10.1504/IJESDF.2013.058653

Campus : Coimbatore

School : School of Physical Sciences

Department : Mathematics

Year : 2013

Abstract : Botnet has become a prevalent platform for many malicious attacks and hence it is considered as a serious threat to internet security. A botmaster can control millions of compromised systems using command & control C&C infrastructure. At early time IRC protocol-based botnets were used by the attackers. Recently attackers have shifted their paradigm towards HTTP-based C&C server because of several advantages and in this situation, bots frequently request and download commands from web servers which are under the control of botmaster. Since web-based C&C bots try to blend into normal HTTP traffic, it is difficult to identify HTTP botnets. In this work, we propose a hidden semi-Markov model HsMM to characterise the normal network behaviour considering that most of the communications of web-based bots are based on TCP. We use TCP-based MIB variables as observed sequence and forward-backward algorithm for estimating model parameters to best account for an observed sequence. Several experiments are conducted to validate our model. The proposed system is lightweight and real time.

Cite this Research Publication : Venkatesh, G. K., Srihari, V., Veeramani, R., Karthikeyan, R. M., &Anitha, R. (2013). Http botnet detection using hidden semi-markov model with snmpmib variables. International Journal of Electronic Security and Digital Forensics, 5(3-4), 188-200

Admissions Apply Now