• No results found

Proactive Botnet Detection and Defense at Internet scale

N/A
N/A
Protected

Academic year: 2021

Share "Proactive Botnet Detection and Defense at Internet scale"

Copied!
1
0
0

Bezig met laden.... (Bekijk nu de volledige tekst)

Hele tekst

(1)

Proactive Botnet Detection and Defense at Internet scale

A collaborative approach

Contact:

Christian Dietz

1,2

Anna Sperotto

2

Gabi Dreo Rodosek

1

Aiko Pras

2

1

CODE - Research center cyber defense,

Universität der Bundeswehr München, München, Germany

{christian.dietz, gabi.dreo}@unibw.de

2

Design and Analysis of Communication Systems (DACS),

University of Twente, Enschede, The Netherlands

{c.dietz, a.sperotto,a.pras}@utwente.nl

Research Questions:

RQ 1:

What do bots need to be deployed and to form a new or join an existing botnet?

RQ 2:

How do bots interact with central internet services, like the domain name service (DNS)?

RQ 3:

How can the interacation with central services be used for detection before botnets can evolve their full size an power?

Approach:

Detection and mitigation of botnets before they evolve their full size and attack power.

Problem:

Botnets enable various cyber-criminal activities

[1,2]

.

References:

[1] Christian Dietz, Anna Sperotto, Gabi Dreo, Aiko Pras: How to achieve early botnet detection at the provider level? In Proceedings of Autonomous Infrastructure, Management and Security (AIMS) Conference, June 2016 ,Springer, DE

[2] van der Wagen, Wytske, and Wolter Pieters: From Cybercrime to Cyborg Crime: Botnets as Hybrid Criminal Actor-Networks. British Journal of Criminology 55.3 (2015): 578-595.

[3] Roland van Rijswijk-Deij, Mattijs Jonker, Anna Sperotto and Aiko Pras: The Internet of Names: A DNS Big Dataset. In Proceedings of ACM SIGCOMM 2015, 17-21 August 2015, London, UK

[3]

Referenties

GERELATEERDE DOCUMENTEN

By means of phase Doppler particle analysis, three velocity components, their higher order moments, and sizes of droplets were measured, showing high intensity velocity fluctuations

Research by Marcel Karperien and colleagues now identifies the bone morphogenetic protein antagonist Gremlin 1 (GREM1), as well as Frizzled–related protein (FRZB) and

Afrikaans: Hoer Handelskole, Parkstraat (Pretoria ) (2), Dis- covery; Hoer Hand el- en Tegniese Skole, Vereeniging, Klerks- dorp; Tegniese Kolleges, Bloemfontein,

Label-free detection of the interaction between specific receptors on the cell surface and their ligands using SPRi would have distinct technical advantages compared to

Our results indicate differences in response of stem cells to photons and carbon ions at different LETs and relative resistance to particle irradiation of salivary gland stem

Als uit dit onderzoek blijkt dat kinderen met en zonder rekenproblemen een gelijk non-symbolisch gevoel voor hoeveelheden hebben, maar een verminderd symbolisch gevoel

Ook werden er verschillende correlaties berekend tussen de criterium variabele, percentielscores op Vmbo – kbl en Mavo, die behaald waren op het Citovolgsysteem Voortgezet Onderwijs

(2009) explain the effect by arguing that cultural distance has a positive effect on the performance of international VC (by assessing the exit types), because