International Journal of Information and Network Security, Volume (3), No (2), Year (2014-5) , Pages (116-127)

Title : ( A survey on real world botnets and detection mechanisms )

Authors: somayeh soltani , Seyed Amin Hosseini Seno , Maryam Nezhad kamali , rahmat Budiarto ,

Access to full-text not allowed by authors

Mitigating the destructive effect of botnets is a concern of security scholars. Though various mechanisms are proposed for botnets detection, real world botnets still survive and do their harmful operations. Botnets have developed new evasion techniques and covert communication channels. Knowing the characteristics of real world botnets helps security researchers in developing more robust detection methods. There are some surveys in the literature that study botnet detection methods; however they do not advert to real world botnets a lot. In this paper, we study various aspects of several real world botnets, i.e. Conficker, Kraken, Rustock, Storm, TDL4, Torpig, Waledac, Zeus and P2P Zeus. Architecture, protocol, type of infection, communication interval, attacks and evasion techniques of these botnets are probed in this paper. Moreover, studies on mitigation and detection of various aspects of botnets and new trends in botnet communication channels are reviewed.


botnet, domain flux, fast flux service network, DDoS, drive-by download, rootkit, covert channel
