vix.ing · top · new · best · stats · spec

AutoBotCatcher: Blockchain-based P2P Botnet Detection for the Internet\n of Things

2018/09/27 by Gokhan Sagirlar, Sagirlar, Gokhan, Barbara Carminati +3
Computer Science · #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting #Network Security and Intrusion Detection

paper · pdf · doi:10.48550/arxiv.1809.10775

openalex publication_date 2018/09/27 · openalex created_date 2022/10/01 · openalex updated_date 2026/07/28

Abstract

In general, a botnet is a collection of compromised internet computers,\ncontrolled by attackers for malicious purposes. To increase attacks' success\nchance and resilience against defence mechanisms, modern botnets have often a\ndecentralized P2P structure. Here, IoT devices are playing a critical role,\nbecoming one of the major tools for malicious parties to perform attacks.\nNotable examples are DDoS attacks on Krebs on Security and DYN, which have been\nperformed by IoT devices part of botnets.\n We take a first step towards detecting P2P botnets in IoT, by proposing\nAutoBotCatcher, whose design is driven by the consideration that bots of the\nsame botnet frequently communicate with each other and form communities. As\nsuch, the purpose of AutoBotCatcher is to dynamically analyze communities of\nIoT devices, formed according to their network traffic flows, to detect\nbotnets. AutoBotCatcher exploits a permissioned Byzantine Fault Tolerant (BFT)\nblockchain, as a state transition machine that allows collaboration of a set of\npre-identified parties without trust, in order to perform collaborative and\ndynamic botnet detection by collecting and auditing IoT devices' network\ntraffic flows as blockchain transactions.\n In this paper, we focus on the design of the AutoBotCatcher by first defining\nthe blockchain structure underlying AutoBotCatcher, then discussing its\ncomponents.\n

Citations

Related