BotCloud: Detecting Botnets Using MapReduce - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

BotCloud: Detecting Botnets Using MapReduce

Résumé

Botnets are a major threat of the current Internet. Understanding the novel generation of botnets relying on peer-to-peer networks is crucial for mitigating this threat. Nowadays, botnet traffic is mixed with a huge volume of benign traffic due to almost ubiquitous high speed networks. Such networks can be monitored using IP flow records but their forensic analysis form the major computational bottleneck. We propose in this paper a distributed computing framework that leverages a host dependency model and an adapted PageRank algorithm. We report experimental results from an open-source based Hadoop cluster and highlight the performance benefits when using real network traces from an Internet operator.
Fichier principal
Vignette du fichier
wifs11.pdf (365.85 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00658186 , version 1 (10-01-2012)

Identifiants

  • HAL Id : hal-00658186 , version 1

Citer

Jérôme François, Shaonan Wang, Walter Bronzi, Radu State, Thomas Engel. BotCloud: Detecting Botnets Using MapReduce. International Workshop on Information Forensics and Security - WIFS, Nov 2011, Foz do Iguaçu, Brazil. Paper #55. ⟨hal-00658186⟩
181 Consultations
1142 Téléchargements

Partager

Gmail Facebook X LinkedIn More