ETRI-Knowledge Sharing Plaform

ENGLISH

성과물

논문 검색
구분 SCI
연도 ~ 키워드

상세정보

학술대회 Study of Host-Based Cyber Attack Precursor Symptom Detection Algorithm
Cited 0 time in scopus Download 0 time Share share facebook twitter linkedin kakaostory
저자
송재구, 김종현, 서동일, 소우영, 김석수
발행일
201012
출처
International Conference on Future Generation Communication and Networking (FGCN) 2010 (CCIS 120), v.120, pp.268-275
DOI
https://dx.doi.org/10.1007/978-3-642-17604-3_32
협약과제
10MS4800, 전역적 협력기반의 통합보안제어 시스템 개발, 김종현
초록
Botnet-based cyber attacks cause large-scale damage with increasingly intelligent tools, which has called for varied research on bot detection. In this study, we developed a method of monitoring behaviors of host-based processes from the point that a bot header attempts to make zombie PCs, detecting cyber attack precursor symptoms. We designed an algorithm that figures out characteristics of botnet which attempts to launch malicious behaviors by means of signature registration, which is for process/reputation/network traffic/packet/source analysis and a white list, as a measure to respond to bots from the end point. © 2010 Springer-Verlag Berlin Heidelberg.
KSP 제안 키워드
Bot Detection, Cyber attacks, Detection algorithm, Host-based, Intelligent tools, Network Traffic, Source analysis, end point, large-scale