Botnets, networks of compromised machines remotely controlled and instructed to work in a coordinated fashion, have had an epidemic diffusion over the Internet and represent one of today's most insidious threat. In this paper, we present an open framework called Dorothy that permits to monitor the activity of a botnet. We propose to characterize a botnet behavior through a set of parameters and a graphical representation. In a case study, we infiltrated and monitored a botnet named siwa collecting information about its functional structure, geographical distribution, communication mechanisms, command language and operations.
|Titolo:||The Dorothy project : an open botnet analysis framework for automatic tracking and activity visualization|
CREMONINI, MARCO (Primo)
|Settore Scientifico Disciplinare:||Settore INF/01 - Informatica|
|Data di pubblicazione:||2010|
|Digital Object Identifier (DOI):||10.1109/EC2ND.2009.15|
|Tipologia:||Book Part (author)|
|Appare nelle tipologie:||03 - Contributo in volume|