A host-based approach to BotNet investigation?

13Citations
Citations of this article
22Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Robot Networks (BotNets) are one of the most serious threats faced by the online community today. Since their appearance in the late 1990's, much effort has been expended in trying to thwart their unprecedented growth. However, with robust and advanced capabilities, it is very difficult for average users to avoid or prevent infection by BotNet malware. Moreover, whilst BotNets have increased in scale, scope and sophistication, the dearth of standardized and effective investigative procedures poses huge challenges to digital investigators in trying to probe such cases. In this paper we present a practical (and repeat-able) host-based investigative methodology to the collection of evidentiary information from a Bot-infected machine. Our approach collects digital traces from both the network and physical memory of the infected local host, and correlates this information to identify the resident BotNet malware involved. © Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering 2010.

Cite

CITATION STYLE

APA

Law, F. Y. W., Chow, K. P., Lai, P. K. Y., & Tse, H. K. S. (2010). A host-based approach to BotNet investigation? In Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering (Vol. 31 LNICST, pp. 161–170). https://doi.org/10.1007/978-3-642-11534-9_16

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free