Challenges of Accurately Measuring Churn in P2P Botnets

Leon Böck, Shankar Karuppayah, Kory Fong, Max Mühlhäuser, Emmanouil Vasilomanolakis

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

Resumé

Peer-to-peer (P2P) botnets are known to be highly resilient to takedown attempts. Such attempts are usually carried out by exploiting vulnerabilities in the bots communication protocol. However, a failed takedown attempt may alert botmasters and allow them to patch their vulnerabilities to thwart subsequent attempts. As a promising solution, takedowns could be evaluated in simulation environments before attempting them in the real world. To ensure such simulations are as realistic as possible, the churn behavior of botnets must be understood and measured accurately. This paper discusses potential pitfalls when measuring churn in live P2P botnets and proposes a botnet monitoring framework for uniform data collection and churn measurement for P2P botnets.
OriginalsprogEngelsk
TitelACM Conference on Computer and Communications Security (CCS)
Antal sider3
ForlagAssociation for Computing Machinery
Publikationsdato2019
Sider2661-2663
ISBN (Trykt)978-1-4503-6747-9
DOI
StatusUdgivet - 2019
BegivenhedProceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security: CCS`19 - London, Storbritannien
Varighed: 11 nov. 201915 nov. 2019

Konference

KonferenceProceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
LandStorbritannien
ByLondon
Periode11/11/201915/11/2019

Fingerprint

Botnet
Network protocols
Monitoring

Citer dette

Böck, L., Karuppayah, S., Fong, K., Mühlhäuser, M., & Vasilomanolakis, E. (2019). Challenges of Accurately Measuring Churn in P2P Botnets. I ACM Conference on Computer and Communications Security (CCS) (s. 2661-2663). Association for Computing Machinery. https://doi.org/10.1145/3319535.3363281
Böck, Leon ; Karuppayah, Shankar ; Fong, Kory ; Mühlhäuser, Max ; Vasilomanolakis, Emmanouil. / Challenges of Accurately Measuring Churn in P2P Botnets. ACM Conference on Computer and Communications Security (CCS). Association for Computing Machinery, 2019. s. 2661-2663
@inproceedings{0f3a2b3a8ddc4853b065870db86db901,
title = "Challenges of Accurately Measuring Churn in P2P Botnets",
abstract = "Peer-to-peer (P2P) botnets are known to be highly resilient to takedown attempts. Such attempts are usually carried out by exploiting vulnerabilities in the bots communication protocol. However, a failed takedown attempt may alert botmasters and allow them to patch their vulnerabilities to thwart subsequent attempts. As a promising solution, takedowns could be evaluated in simulation environments before attempting them in the real world. To ensure such simulations are as realistic as possible, the churn behavior of botnets must be understood and measured accurately. This paper discusses potential pitfalls when measuring churn in live P2P botnets and proposes a botnet monitoring framework for uniform data collection and churn measurement for P2P botnets.",
keywords = "botnets, churn, P2P botnets",
author = "Leon B{\"o}ck and Shankar Karuppayah and Kory Fong and Max M{\"u}hlh{\"a}user and Emmanouil Vasilomanolakis",
year = "2019",
doi = "10.1145/3319535.3363281",
language = "English",
isbn = "978-1-4503-6747-9",
pages = "2661--2663",
booktitle = "ACM Conference on Computer and Communications Security (CCS)",
publisher = "Association for Computing Machinery",
address = "United States",

}

Böck, L, Karuppayah, S, Fong, K, Mühlhäuser, M & Vasilomanolakis, E 2019, Challenges of Accurately Measuring Churn in P2P Botnets. i ACM Conference on Computer and Communications Security (CCS). Association for Computing Machinery, s. 2661-2663, London, Storbritannien, 11/11/2019. https://doi.org/10.1145/3319535.3363281

Challenges of Accurately Measuring Churn in P2P Botnets. / Böck, Leon; Karuppayah, Shankar ; Fong, Kory; Mühlhäuser, Max; Vasilomanolakis, Emmanouil.

ACM Conference on Computer and Communications Security (CCS). Association for Computing Machinery, 2019. s. 2661-2663.

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

TY - GEN

T1 - Challenges of Accurately Measuring Churn in P2P Botnets

AU - Böck, Leon

AU - Karuppayah, Shankar

AU - Fong, Kory

AU - Mühlhäuser, Max

AU - Vasilomanolakis, Emmanouil

PY - 2019

Y1 - 2019

N2 - Peer-to-peer (P2P) botnets are known to be highly resilient to takedown attempts. Such attempts are usually carried out by exploiting vulnerabilities in the bots communication protocol. However, a failed takedown attempt may alert botmasters and allow them to patch their vulnerabilities to thwart subsequent attempts. As a promising solution, takedowns could be evaluated in simulation environments before attempting them in the real world. To ensure such simulations are as realistic as possible, the churn behavior of botnets must be understood and measured accurately. This paper discusses potential pitfalls when measuring churn in live P2P botnets and proposes a botnet monitoring framework for uniform data collection and churn measurement for P2P botnets.

AB - Peer-to-peer (P2P) botnets are known to be highly resilient to takedown attempts. Such attempts are usually carried out by exploiting vulnerabilities in the bots communication protocol. However, a failed takedown attempt may alert botmasters and allow them to patch their vulnerabilities to thwart subsequent attempts. As a promising solution, takedowns could be evaluated in simulation environments before attempting them in the real world. To ensure such simulations are as realistic as possible, the churn behavior of botnets must be understood and measured accurately. This paper discusses potential pitfalls when measuring churn in live P2P botnets and proposes a botnet monitoring framework for uniform data collection and churn measurement for P2P botnets.

KW - botnets

KW - churn

KW - P2P botnets

U2 - 10.1145/3319535.3363281

DO - 10.1145/3319535.3363281

M3 - Article in proceeding

SN - 978-1-4503-6747-9

SP - 2661

EP - 2663

BT - ACM Conference on Computer and Communications Security (CCS)

PB - Association for Computing Machinery

ER -

Böck L, Karuppayah S, Fong K, Mühlhäuser M, Vasilomanolakis E. Challenges of Accurately Measuring Churn in P2P Botnets. I ACM Conference on Computer and Communications Security (CCS). Association for Computing Machinery. 2019. s. 2661-2663 https://doi.org/10.1145/3319535.3363281