Title
Detection and prevention of botnets and malware in an enterprise network
Abstract
One of the most significant threats faced by enterprise networks is from bots. A bot is a program that operates as an agent for a user and runs simulated tasks over the internet, at a much higher rate than would be possible for a human alone. A collection of bots in a network, used for malicious purposes, is referred to as botnet. Our proposed novel approach can detect and combat bots, adopting a two-pronged strategy, using a stand-alone and a network algorithm. The stand-alone algorithm, which runs independently on each node of the network, monitors active processes on the node and triggers the network algorithm when a suspicious process is identified. The network algorithm will then analyse conversations to and from the hosts to deduce the bot pattern and bot signatures which can subsequently be used by the stand-alone algorithm to thwart bot processes at their very onset.
Year
DOI
Venue
2013
10.1504/IJWMC.2012.046776
International Journal of Wireless and Mobile Computing
Keywords
DocType
Volume
bot signature,active process,network algorithm,bot process,analyse conversation,stand-alone algorithm,bot pattern,enterprise network,combat bots,higher rate,botnets,malware,distributed denial of service,dynamic time warping,ddos
Journal
abs/1312.1629
Issue
Citations 
PageRank 
2
4
0.42
References 
Authors
9
8