HAL will be down for maintenance from Friday, June 10 at 4pm through Monday, June 13 at 9am. More information
Skip to Main content Skip to Navigation
Conference papers

BotFP: FingerPrints Clustering for Bot Detection

Agathe Blaise 1, 2 Mathieu Bouet 2 Vania Conan 2 Stefano Secci 3
1 Phare
LIP6
3 CEDRIC - ROC - CEDRIC. Réseaux et Objets Connectés
CEDRIC - Centre d'études et de recherche en informatique et communications
Abstract : Efficient bot detection is a crucial security matter and has been widely explored in the past years. Recent approaches supplant flow-based detection techniques and exploit graph-based features, incurring however in scalability issues in terms of time and space complexity. Bots exhibit specific communication patterns: they use particular protocols, contact specific domains, hence can be identified by analyzing their communication with the outside. To simplify the communication graph, we look at frequency distributions of protocol attributes capturing the specificity of botnets behaviour. In this paper, we propose a bot detection technique named BotFP, for BotFinger-Printing, which acts by (i) characterizing hosts behaviour with attribute frequency distribution signatures, (ii) learning behaviour of benign hosts and bots through a clustering technique, and (iii) classifying new hosts based on distances to labelled clusters. We validate our solution on the CTU-13 dataset, which contains 13 scenarios of bot infections, connecting to a Command-and-Control (C&C) channel and launching malicious actions such as port scanning or Denial-of-Service (DDoS) attacks. Our approach applies to various bot activities and network topologies. The approach is lightweight, can handle large amounts of data, and shows better accuracy than state-of-the-art techniques.
Complete list of metadata

Cited literature [21 references]  Display  Hide  Download

https://hal.archives-ouvertes.fr/hal-02501912
Contributor : Stefano Secci Connect in order to contact the contributor
Submitted on : Sunday, March 8, 2020 - 3:05:52 PM
Last modification on : Monday, April 4, 2022 - 10:40:41 AM
Long-term archiving on: : Tuesday, June 9, 2020 - 12:54:30 PM

File

201488_1.pdf
Files produced by the author(s)

Identifiers

Citation

Agathe Blaise, Mathieu Bouet, Vania Conan, Stefano Secci. BotFP: FingerPrints Clustering for Bot Detection. IEEE/IFIP Network Operations and Management Symposium (NOMS), Apr 2020, Budapest, Hungary. ⟨10.1109/NOMS47738.2020.9110420⟩. ⟨hal-02501912⟩

Share

Metrics

Record views

226

Files downloads

526