Skip to main content

Are your hosts trading or plotting? Telling P2P file-sharing and bots apart

Publication ,  Conference
Yen, TF; Reiter, MK
Published in: Proceedings - International Conference on Distributed Computing Systems
August 27, 2010

Peer-to-peer (P2P) substrates are now widely used for both file-sharing and botnet command-and-control. Despite the commonality of their substrates, we show that the different goals and circumstances of these applications give rise to behaviors that can be distinguished in network flow records. Using features related to traffic volume, "churn" among peers, and differences between human-driven and machine-driven traffic, we develop a technique for identifying P2P bots (the Plotters) and, in particular, separating them from file-sharing hosts (the Traders). Evaluations performed on traffic recorded at the edge of a university network show that we can achieve, e.g., 87.50% detection of Storm bots with a 0.47% false positive rate. We also demonstrate the significant extent to which Plotter behaviors would need to change to evade our technique. © 2010 IEEE.

Duke Scholars

Published In

Proceedings - International Conference on Distributed Computing Systems

DOI

Publication Date

August 27, 2010

Start / End Page

241 / 252
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Yen, T. F., & Reiter, M. K. (2010). Are your hosts trading or plotting? Telling P2P file-sharing and bots apart. In Proceedings - International Conference on Distributed Computing Systems (pp. 241–252). https://doi.org/10.1109/ICDCS.2010.76
Yen, T. F., and M. K. Reiter. “Are your hosts trading or plotting? Telling P2P file-sharing and bots apart.” In Proceedings - International Conference on Distributed Computing Systems, 241–52, 2010. https://doi.org/10.1109/ICDCS.2010.76.
Yen TF, Reiter MK. Are your hosts trading or plotting? Telling P2P file-sharing and bots apart. In: Proceedings - International Conference on Distributed Computing Systems. 2010. p. 241–52.
Yen, T. F., and M. K. Reiter. “Are your hosts trading or plotting? Telling P2P file-sharing and bots apart.” Proceedings - International Conference on Distributed Computing Systems, 2010, pp. 241–52. Scopus, doi:10.1109/ICDCS.2010.76.
Yen TF, Reiter MK. Are your hosts trading or plotting? Telling P2P file-sharing and bots apart. Proceedings - International Conference on Distributed Computing Systems. 2010. p. 241–252.

Published In

Proceedings - International Conference on Distributed Computing Systems

DOI

Publication Date

August 27, 2010

Start / End Page

241 / 252