Chinese Journal of Network and Information Security ›› 2023, Vol. 9 ›› Issue (1): 42-55.doi: 10.11959/j.issn.2096-109x.2023002

• Papers • Previous Articles     Next Articles

Secure controlling method for scalable botnets

Qiang LIU1, Pengfei LI1, Zhangjie FU2   

  1. 1 College of Computer, National University of Defense Technology, Changsha 410073, China
    2 School of Computer &Software, Nanjing University of Information Science &Technology, Nanjing 210044, China
  • Revised:2022-07-01 Online:2023-02-25 Published:2023-02-01
  • Supported by:
    The Natural Science Foundation of Hunan Province(2021JJ30779)

Abstract:

Botnet is one of main threats towards the Internet.Currently, botnets can expand to the whole world due to various types of network services, pervasive security vulnerabilities and massive deployment of networked devices, e.g., internet of things (IoT) devices.Future botnets will become more cross-platform and stealthy, which introduces severe security risks to cyberspace.Therefore, in-depth research on botnets can offer study targets to corresponding defensive studies, which is very meaningful for designing an architecture to secure the next-generation cyberspace.Hence, an HTTP-based scalable botnet framework was proposed to address the problems of compatibility, stealthiness and security.Specifically, the framework adopted a centralized controlling model.Moreover, it used the HTTP protocol as the designed botnet’s communication protocol and block encryption mechanisms based on symmetric cryptography to protect the botnet’s communication contents.Furthermore, a secure control mechanism for multi-platform botnets was designed.In particular, the proposed mechanism utilized source-level code integration and cross-compilation techniques to solve the compatibility challenge.It also introduced encrypted communication with dynamic secret keys to overcome the drawbacks of network traffic regularity and ease of analysis in traditional botnets.Moreover, it designed server migration and reconnection mechanisms to address the weakness of single-point-failure in centralized botnet models.Simulation results in three experimental scenarios with different levels of botnet controllability show that there is a linear relationship between the size of a botnet and the service overhead of the related C&C servers.In addition, under the condition of the same botnet scale, a higher level of controllability introduces a higher throughput and a greater system overhead.The above results demonstrate the effectiveness and the practical feasibility of the proposed method.

Key words: botnet, secure control, multi-platform architecture, advanced encryption standard

CLC Number: 

No Suggested Reading articles found!