Download presentation
Presentation is loading. Please wait.
1
Modeling Botnet Propagation Using Time Zones
Published by: Cliff Zou, David Dagon, Wenke Lee Presentation by: Corey Kuwanoe
2
Outline Background Data Collection Model Experiments Practical Usage
Time Zone Diurnal Experiments Practical Usage
3
Background Botnets
4
Background (cont.) Heterogeneous Victims obtained through Viruses
Worms Trojans
5
Data Collection Command and Control Servers Honeypots DNS manipulation
6
Time Zone Modeling Diurnal Shaping Function (t)
Fraction of vulnerable computers online at time t Periodical function 24 hr period
7
Diurnal Model for Single Time Zone
I(t) Number of infected hosts S(t) Number of vulnerable hosts N(t) Number of hosts that were originally vulnerable
8
Diurnal Model for Single Time Zone (cont.)
I’(t) (t)I(t) # of online infected hosts S’(t) (t)S(t) # of online vulnerable hosts N’(t) (t)N(t) # of online hosts from N(t)
9
Diurnal Model for Single Time Zone (cont.)
Worm propagation dynamics Worm propagation diurnal model = proportion of scan rate / ip space = removal parameter
10
Diurnal Model for Single Time Zone (cont.)
11
Diurnal Model for Multiple Time Zones
Groups 24 groups for 24 hours
12
Experiments Botnet Grouping 350k members Random scanning Single Domain
North America Asia Europe
13
Experiments (cont.)
14
Experiments (cont.)
15
Experiments (cont.)
16
Experiments (cont.) Automatically derive (t)
Break down botnet traffic by region Process regional data Split dataset into segments Normalize data in segments Average data in segments Remove monitor noise Normalize result Place (t) in database
17
Experiments (cont.)
18
Practical Uses Time for releasing a worm Predict future propagation
19
Practical Uses (cont.)
20
Practical Uses (cont.)
21
Practical Uses (cont.)
22
Practical Uses (cont.) Successfully predicts dynamics of botnets
Not infected populations
23
Contributions Simple and intuitive model
Accurate predictions of future propagation
24
Weaknesses Only accurate for scanning worms
worms/viruses pose a problem to model Predictions are only good for a limited amount of time Does not address multiple infection vectors
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.