Logo des Repositoriums
 
Konferenzbeitrag

A Privacy-Preserving Architecture for Collaborative Botnet Detection

Vorschaubild nicht verfügbar

Volltext URI

Dokumententyp

Text/Conference Paper

Zusatzinformation

Datum

2024

Autor:innen

Zeitschriftentitel

ISSN der Zeitschrift

Bandtitel

Verlag

Gesellschaft für Informatik e.V.

Zusammenfassung

Detecting communication with command and control (C2) servers and outbound attacks from internal bots (botnet traffic) is critical for network operators. Detection of botnet traffic is typically done by analyzing communication patterns in their own networks. We hypothesise that cooperation between different network operators can improve the detection of botnet traffic, as a larger amount of traffic can be examined. However, network operators do normally not want to share their traffic with others for privacy reasons. We therefore present a privacy-preserving architecture for collaborative botnet detection. To this end, network operators interested in detecting botnet traffic share traffic from their own networks by using a Threshold Multi-Party Private Set Intersection (T-MP-PSI) protocol to ensure that shared traffic details, such as IP addresses, are only disclosed if they occur on a minimum number of networks. We present the main results from a preliminary evaluation of the architecture based on publicly available benchmark data sets. The evaluation shows that our architecture contributes to the detection of botnet traffic, but that a high number of false positives also occur. However, this high number can be reduced by pre-processing measures. We also present further options for evaluating the architecture.

Beschreibung

Dessani, Leo (2024): A Privacy-Preserving Architecture for Collaborative Botnet Detection. Sicherheit 2024. DOI: 10.18420/sicherheit2024_022. Bonn: Gesellschaft für Informatik e.V.. PISSN: 1617-5468. ISBN: 978-3-88579-739-5. pp. 289-294. Promovierendenforum. Worms. 09.-11.04.2024

Zitierform

Tags