Offense Questions: Botnet detection - PowerPoint PPT Presentation

1 / 2
About This Presentation
Title:

Offense Questions: Botnet detection

Description:

Even IRC-based detection seems hopeless in the paper. Maybe also consider semantics, not just numerical values, like traffic size, ... – PowerPoint PPT presentation

Number of Views:50
Avg rating:3.0/5.0
Slides: 3
Provided by: yanc8
Category:

less

Transcript and Presenter's Notes

Title: Offense Questions: Botnet detection


1
Offense Questions Botnet detection
  • What is the difference b/t bot and pure worms
  • CC ?
  • Can we automatically detect CC ? How?
  • No real invariants/separator in CC traffic ?
  • Even IRC-based detection seems hopeless in the
    paper
  • Maybe also consider semantics, not just numerical
    values, like traffic size, length of packets,
    etc.
  • Fundamental difference human vs. machine !
  • What about URL-based botnet?

2
Offense Questions Botnet detection II
  • Detection based on specific bot commands ?
  • Specific bot dependent
  • Can be encrypted
  • Statistical finger printing techniques ?
  • Contradict w/ the U Michigan paper
Write a Comment
User Comments (0)
About PowerShow.com