Download presentation
Presentation is loading. Please wait.
Published byClare Reed Modified over 9 years ago
1
Real-Time Botnet Command and Control Characterization at the Host Level 2013.10.24 JHEN-HUANG Gao
2
Title: Real-Time Botnet Command and Control Characterization at the Host Level Author & Institution : Farhood Farid Etemad Payam Vahdani Publication: 6'th International Symposium on Telecommunications Year: 2012 Cited (Google): 0 Basic Information 1/7
3
Introduction Architecture Detect bot Real – Time Filtering Conclusion Outline 2/7
4
Botnet 、 other kind of malwares C&C is centralized or decentralized Botnet can cause many problem Normal solution Introduction 3/7
5
IRC protocol string NICK 、 PASS 、 USER 、 JOIN 、 PRVIMSG 、 OPER 、 MOTD ex Get me the file “website.html” ClientSever “Here is the file” followed by the file’s content HTTP protocol GET 、 POST 、 HEAD Architecture 4/7
6
IRC PART Td>Tdh : normal IRC Td<Tdh : malicious IRC HTTP PART Detect bot 5/7
7
Filtering malicious traffic after detection Real – Time Filtering 6/7
8
Real-time‘s method : Advantage Find bot immediately Simple to use Weakness Can’t be use on decentralized Conclusion 7/7
9
THANK YOU
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.