COFFEE: a Concept based on OpenFlow to Filter and Erase Events of botnet activity at high-speed nodes
نویسندگان
چکیده
It is a great challenge to tackle the increasing threat of botnets to contemporary networks. The community developed a lot of approaches to detect botnets. Their fundamental idea differs and may be grouped according to the location (e.g., host-based, network-based), data sets (e.g., full network packets, packet header information), and algorithms (e.g., signature based, anomaly based). However, if applied to high-speed networks like nodes of an Internet service provider (ISP) currently proposed methods suffer from two drawbacks. First, the false positive rate is too high to be used in an operational environment. Second, mitigation and reaction is not addressed. In this paper we introduce COFFEE, our concept of a botnet detection and mitigation framework at large-scale networks. The overall goal of COFFEE is to keep operational costs to a minimum. The detection part of COFFEE comprises two phases: the first one processes the whole traffic to filter candidates of a command-and-control communication using NetFlow-based detection algorithms. In order to decrease the false positive rate, suspected network connections are inspected in more detail in the second phase. The second phase makes use of the concept of Software-Defined Networking (SDN), which is currently deployed in some networks. If the detection yields an alert, SDN again is used to react (e.g., to drop suspect connections).
منابع مشابه
Coffee Houses at Qajar age an Infrastructure for Folk Art Boom
The present research with an emphasis on coffee houses at Qajar age has recognized motives and effect of social and political factors such as conditional event in formation of art traditions in coffee house so as to examine the communication function of coffee house painting at this space. Coffee house at Qajar age has been found as a place for people’s gathering which had communicative-cultura...
متن کاملMiniaturized High-Pass Filter Based on Balanced Composite Right-Left Handed Transmission Line Using Meander Spiral Complementary Split Ring Resonators
In this paper, a compact high-pass filter (HPF) with a sharp rejection response based on the balanced composite right-left handed (CRLH) transmission line (TL) concept is proposed. A series LC resonator using an interdigital capacitor and meander lines is designed. Also, a meander spiral complementary split ring resonator (MSCSRR) is used to realize the parallel LC resonator. The high-pass filt...
متن کاملHigh Speed Delay-Locked Loop for Multiple Clock Phase Generation
In this paper, a high speed delay-locked loop (DLL) architecture ispresented which can be employed in high frequency applications. In order to design the new architecture, a new mixed structure is presented for phase detector (PD) and charge pump (CP) which canbe triggered by double edges of the input signals. In addition, the blind zone is removed due to the elimination of reset signal. Theref...
متن کاملBotOnus: an online unsupervised method for Botnet detection
Botnets are recognized as one of the most dangerous threats to the Internet infrastructure. They are used for malicious activities such as launching distributed denial of service attacks, sending spam, and leaking personal information. Existing botnet detection methods produce a number of good ideas, but they are far from complete yet, since most of them cannot detect botnets in an early stage ...
متن کاملTowards Wire-speed Platform-agnostic Control of OpenFlow Switches
The possibility to offload, via a platform-agnostic specification, the execution of (some/part of the) control functions down to the switch and operate them at wire speed based on packet level events, would yield significant benefits in terms of control latency and reaction times, meanwhile retaining the SDN-type ability to program and instantiate a desired network operation from a central cont...
متن کامل