Understanding botclouds from a system perspective: A principal component analysis

Hammi Badis, Guillaume Doyen, Rida Khatoun

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Cloud computing is gaining ground and becoming one of the fast growing segments of the IT industry. However, if its numerous advantages are mainly used to support a legitimate activity, it is now exploited for a use it was not meant for: malicious users leverage its power and fast provisioning to turn it into an attack support. Botnets supporting DDoS attacks are among the greatest beneficiaries of this malicious use since they can be setup on demand and at very large scale without requiring a long dissemination phase nor an expensive deployment costs. For cloud service providers, preventing their infrastructure from being turned into an Attack as a Service delivery model is very challenging since it requires detecting threats at the source, in a highly dynamic and heterogeneous environment. In this paper, we present the result of an experiment campaign we performed in order to understand the operational behavior of a botcloud used for a DDoS attack. The originality of our work resides in the consideration of system metrics that, while never considered for state-of-the-art botnets detection, can be leveraged in the context of a cloud to enable a source based detection. Our study considers both attacks based on TCP-flood and UDP-storm and for each of them, we provide statistical results based on a principal component analysis, that highlight the recognizable behavior of a botcloud as compared to other legitimate workloads.

Original languageEnglish
Title of host publicationIEEE/IFIP NOMS 2014 - IEEE/IFIP Network Operations and Management Symposium
Subtitle of host publicationManagement in a Software Defined World
PublisherIEEE Computer Society
ISBN (Print)9781479909131
DOIs
Publication statusPublished - 1 Jan 2014
Externally publishedYes
EventIEEE/IFIP Network Operations and Management Symposium: Management in a Software Defined World, NOMS 2014 - Krakow, Poland
Duration: 5 May 20149 May 2014

Publication series

NameIEEE/IFIP NOMS 2014 - IEEE/IFIP Network Operations and Management Symposium: Management in a Software Defined World

Conference

ConferenceIEEE/IFIP Network Operations and Management Symposium: Management in a Software Defined World, NOMS 2014
Country/TerritoryPoland
CityKrakow
Period5/05/149/05/14

Fingerprint

Dive into the research topics of 'Understanding botclouds from a system perspective: A principal component analysis'. Together they form a unique fingerprint.

Cite this