Second International Conference on Information Systems Security and Privacy

Detecting Botnets Using a Collaborative Situational-aware IDPS

, , and

Botnet attacks turn susceptible victim computers into bots that carry out various malicious activities under the control of a botmaster. Some examples of the damage they cause include denial-of-service attacks, click fraud, spamware, and phishing. These attacks can vary in the types of architecture and communication protocols used, which might be modified over the botnet's lifespan. Intrusion detection and prevention systems are one way to safeguard the cyber-physical systems we use, but they have difficulty detecting new or modified attacks, including botnets. Only known attacks whose signatures have been identified and stored in some form can be discovered by most of these systems. Also, traditional IDPSs are point-based solutions incapable of utilizing information from multiple data sources and have difficulty discovering new or more complex attacks. To address these issues, we are developing a semantic approach to intrusion detection that uses a variety of sensors collaboratively. Leveraging information from these heterogeneous sources yields a more robust, situation-aware IDPS better equipped to detect complex attacks such as botnets.


  • 656516 bytes

ai, botnet detection, botnet, cybersecurity, intrusion detection, ontology, security, situational-aware

InProceedings

SCITEPRESS–Science and Technology Publications, Lda

DOI: 10.5220/0005684902900298

Downloads: 2091 downloads

UMBC ebiquity