Identifying and modeling botnet C&C behaviors

García, S., Uhlíř, V., & Rehak, M. (2014, May). Identifying and modeling botnet C&C behaviors. In Proceedings of the 1st International Workshop on Agents and CyberSecurity (pp. 1-8).

Abstract

Through the analysis of a long-term botnet capture, we identified and modeled the behaviors of its C&C channels. They were found and characterized by periodicity analyses and statistical representations. The relationships found between the behaviors of the UDP, TCP and HTTP C&C channels allowed us to unify them in a general model of the botnet behavior. Our behavioral analysis of the C&C channels gives a new perspective on the modeling of malware behavior, helping to better understand botnets.

Read more: https://dl.acm.org/doi/10.1145/2602945.2602949