标题：Identifying Peer-to-Peer Botnets Through Periodicity Behavior Analysis
作者：Wang, Pengfei ;Wang, Fengyu ;Lin, Fengbo ;Cao, Zhenzhong
作者机构：[Wang, Pengfei ;Wang, Fengyu ;Lin, Fengbo ] School of Computer Science and Technology, Shandong University, Jinan, China;[Cao, Zhenzhong ] School of C 更多
会议名称：17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications and 12th IEEE International Conference on Big Data Science and Engineering, Trustcom/BigDataSE 2018
会议日期：31 July 2018 through 3 August 2018
来源：Proceedings - 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications and 12th IEEE International Conference on Big Data Science and Engineering, Trustcom/BigDataSE 2018
关键词：botnet detection; P2P botnet; periodicity behavior; Spark
摘要：Peer-to-Peer botnets have become one of the significant threat against network security due to their distributed properties. The decentralized nature makes their detection challenging. It is important to take measures to detect bots as soon as possible to minimize their harm. In this paper, we propose PeerGrep, a novel system capable of identifying P2P bots. PeerGrep starts from identifying hosts that are likely engaged in P2P communications, and then distinguishes P2P bots from P2P hosts by analyzing their active ratio, packet size and the periodicity of connection to destination IP addresses. The evaluation shows that PeerGrep can identify all P2P bots with quite low FPR even if the malicious P2P application and benign P2P application coexist within the same host or there is only one bot in the monitored network. © 2018 IEEE.