Botlar tarafından ele geçirilmiş bilgisayarların tespit edilmesi için içerik tabanlı imzaların üretilmesi
Is this your thesis?
This record came from a bulk archive import. If it’s yours, link it to your profile.
Abstract (EN)
A botnet is a network of compromised machines that are remotely controlled andcommanded by an attacker, who is often called the botmaster. Such botnets areoften abused as platforms to launch distributed denial of service attacks, sendspam mails or perform identity theft. In recent years, the basic motivationsfor malicious activity have shifted from script kiddie vandalism in the hackercommunity, to more organized attacks and intrusions for ¯nancial gain. This shiftexplains the reason for the rise of botnets that have capabilities to perform moresophisticated malicious activities. Recently, researchers have tried to developbotnet detection mechanisms. The botnet detection mechanisms proposed to datehave serious limitations, since they either can handle only certain types of botnetsor focus on only speci¯c botnet attributes, such as the spreading mechanism, theattack mechanism, etc., in order to constitute their detection models.We present a system that monitors network tra±c to identify bot-infectedhosts. Our goal is to develop a more general detection model that identi¯essingle infected machines without relying on the bot propagation vector. To thisend, we leverage the insight that all of the bots get a command and perform anaction as a response, since the command and response behavior is the uniquecharacteristic that distinguishes the bots from other malware. Thus, we examinethe network tra±c generated by bots to locate command and response behaviors.Afterwards, we generate signatures from the similar commands that are followedby similar bot responses without any explicit knowledge about the commandand control protocol. The signatures are deployed to an IDS that monitors thenetwork tra±c of a university. Finally, the experiments showed that our systemis capable of detecting bot-infected machines with a low false positive rate.
Author
Leyla Bilge
Institution
How to Cite
Leyla Bilge (Master Thesis). Botlar tarafından ele geçirilmiş bilgisayarların tespit edilmesi için içerik tabanlı imzaların üretilmesi, 2008, İhsan Doğramacı Bilkent University, Bilgisayar Mühendisliği Bölümü.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from İhsan Doğramacı Bilkent University
- Osmanlı Devletinde vergi ve vergi etrafında oluşan ilişkiler üzerine bir çalışma (16.-17. yüzyıllar)(2019)
- Rastsal kümeler ve choquet-tip temsiller(2021)
- Petrol fiyatları ve getiri eğrisi(2024)
- Yalnız yaşamak: Yollar, deneyimler ve gelecek beklentileri(2025)
- Detente dönemine doğru: Johnson Mektubunun ardından Türk dış politikası(2021)
- Geç Antik Çağ'da Aşağı Tuna: Histria örneği(2023)
