Finding Botnet Command and Control Servers by TCP Connections
Date Issued
2010
Date
2010
Author(s)
Chung, Hsi-Shan
Abstract
In recent years, botnets have become serious network security problems. There are lots of malicious activities on the Internet like spam, phishing sites, network detection and attack, illegal file transfer, etc., and a great part of malicious activities was generated by the botnets. Therefore, how to efficient defense botnets is worth to study.
The biggest difference between bots and human users is that the users will not waste too much time and computing ability on the trial and error. After getting several connection errors, human users will try to find the reasons causing the errors, check the software settings or hardware connections to rule out the problem. Normal applications might get connection errors and try to connection several times. However, the normal applications will stop such behavior after a fixed interval or some period of trial and error, and show an error message to inform users to rule out the problem. But the bots behaviors are different. They can try and error day and night, and return the action report back to the botnet owner according the connection results. The biggest difference between the malware of botnet and other types of malicious programs is that bots will establish some command and control channels. The botnet owner can control entire botnet to act and update the malware through those channels. If we can quickly and correctly grasp the command and control channels of the botnets, and block the network connections to the command and control channels according to the results, we can reduce the control ability of botnet owner.
We propose a wide range defense mechanism, setting on the vantage point of the network egress position. This defense mechanism does not check the characteristics of the software or the content in the packet, but focus on the connection failure of transmission control protocol (TCP) on the Internet, an unusually thing of the normal user, looking for the same server''s IP address they access, and check each IP address is belonging to the command and control servers of the botnet or not, based on the entire connection to this channel.
Subjects
Botnet
Command and Control Server (C&C server)
Three-Way Handshake
Passive Anomaly Analysis
Type
thesis
File(s)![Thumbnail Image]()
Loading...
Name
ntu-99-R97921070-1.pdf
Size
23.32 KB
Format
Adobe PDF
Checksum
(MD5):33eeb5eba2deb1330738e0d641c73797
