Botnet Defense System: Concept, Design, and Basic Strategy

Author:

Yamaguchi ShingoORCID

Abstract

This paper proposes a new kind of cyber-security system, named Botnet Defense System (BDS), which defends an Internet of Things (IoT) system against malicious botnets. The concept of BDS is “Fight fire with fire”. The distinguishing feature is that it uses white-hat botnets to fight malicious botnets. A BDS consists of four components: Monitor, Strategy Planner, Launcher, and Command and Control (C&C) server. The Monitor component watches over a target IoT system. If the component detects a malicious botnet, the Strategy Planner component makes a strategy against the botnet. Based on the planned strategy, the Launcher component sends white-hat worms into the IoT system and constructs a white-hat botnet. The C&C server component commands and controls the white-hat botnet to exterminate the malicious botnet. Strategy studies are essential to produce intended results. We proposed three basic strategies to launch white-hat worms: All-Out, Few-Elite, and Environment-Adaptive. We evaluated BDS and the proposed strategies through the simulation of agent-oriented Petri net model representing the battle between Mirai botnets and the white-hat botnets. This result shows that the Environment-Adaptive strategy is the best and reduced the number of needed white-hat worms to 38.5% almost without changing the extermination rate for Mirai bots.

Publisher

MDPI AG

Subject

Information Systems

Reference15 articles.

1. DDoS in the IoT: Mirai and Other Botnets

2. New Mirai Variant Uses Multiple Exploits to Target Routers and Other Deviceshttps://blog.trendmicro.com/trendlabs-security-intelligence/new-mirai-variant-uses-multiple-exploits-to-target-routers-and-other-devices/

Cited by 20 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. BDSsim: A Mesa-Based Simulator for Botnet Defense System;2024 International Technical Conference on Circuits/Systems, Computers, and Communications (ITC-CSCC);2024-07-02

2. Implementation of Infection Environment for White-hat Worm and Malicious Botnet Using Mirai Source Code;2024 12th International Conference on Information and Education Technology (ICIET);2024-03-18

3. Mesa-Based Simulator of Botnet Defense System and Impact Evaluation of Botnet Infection Rates;2024 International Conference on Electronics, Information, and Communication (ICEIC);2024-01-28

4. Estimating the Infection Spread Rate of Malicious Botnets Using Reconnaissance Worms in Botnet Defense System;2023 IEEE International Conference on Consumer Electronics-Asia (ICCE-Asia);2023-10-23

5. Network Hardening Method by Cutting and Re-Linking Based on Exclusive Vulnerabilities;2023 IEEE 12th Global Conference on Consumer Electronics (GCCE);2023-10-10

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3