News
| [2011-9-13] Botnet 成果發表會
|
| - 時間:2011 年 9 月 19 日 (2:30pm)/地點:台大博理館201會議室 |
| [2011-7-10] Botnet project 12th meeting
|
| - 時間:2011年 7 月 15日 (9:30am)/地點:台大電機二館103會議室 |
| [2011-6-20] Botnet project 11th meeting
|
| - 時間:2011年 6 月 23日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-6-20] Botnet project 11th meeting
|
| - 時間:2011年 6 月 23日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-6-7] Botnet project 10th meeting
|
| - 時間:2011年 6 月 9日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-5-23] Botnet project 9th meeting
|
| - 時間:2011年 5 月 26日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-5-9] Botnet project 8th meeting
|
| - 時間:2011年 5 月 12日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-4-21] Botnet project 7th meeting
|
| - 時間:2011年 4 月 28日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-4-11] Botnet project 6th meeting
|
| - 時間:2011年 4 月 14日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-3-30] Botnet project 5th meeting
|
| - 時間:2011年 3 月 31日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-3-2] Botnet project 4th meeting
|
| - 時間:2011年 3 月 17日 (9:30am)/地點:台大電機二館124會議室 |
| [2011-2-10] Botnet project 3rd meeting
|
| - 時間:2011年 2 月 14日 (9:30am)/地點:台大電機二館103會議室 |
| [2011-1-17] 1/31 Botnet project meeting 暫停乙次 |
| |
| [2011-1-13] Botnet project 2nd meeting
|
| - 時間:2011年 1 月 17日 (9:30am)/地點:台大電機二館103會議室 |
| [2010-12-31] Botnet project 1st meeting
|
| - 時間:2011年 1 月 3日 (9:00am)/地點:台大電機二館103會議室 |
| [2010-12-6] 論文研討建議清單
|
| - 2010 Botnet會議論文研討建議清單 |
Project Overview
The botnet is one of the most serious threats in system and network security in recent years. Governed by botmaster, vulnerable servers or routers are attacked, infected, and become part of the botnet afterwards to execute malicious commands such as distributing spams, phishing or DDoS attacks. Often botnet is characterized by its distributed manner. Therefore the intrusion detectors built on only single machine or router is usually not powerful enough to detect the botnet effectively.
Based on this understanding, we build a framework which considers the spatial relationship between servers or routers to detect the existence of botnet and its scale. Also, to consider the relationship in the temporal domain will tell us the speed of the botnet infection. As a whole, based on a segmentation technique with both of the spatial and temporal considerations, we can detect the botnet, its source, its size and its infection pattern. We would like to propose a spatio-temporal Markov model for the botnet detection. Also, due to the common problem of slow convergence in the large-scale Markov model, we shall consider an integrated framework to speed up the convergence. The integrated framework is based on a from-simple-to-complex modeling process.
The project is a two-year project. The first year is devoted to building the system for the data collection. Some typical botnets will be studied and their infection pattern will be used to training our model. We would also study the convergence theory for the iterative algorithm worked on Markov models, considered as loopy graphs. The second year will focus on applying our model to real environment. Different network environment may provide different service and have various behaviors. We would like to make our model an adaptive one so that our botnet detection can be worked on different network environment.