Analysis of Malware Network Activity

  • Gilles Berger-Sabbatel
  • Andrzej Duda
Conference paper
Part of the Communications in Computer and Information Science book series (CCIS, volume 149)


A botnet is a network of zombie computers compromised by some malware (virus, worm). Botnets are coordinated by a botmaster through a command and control channel (C&C) to which the malware connects to get instructions. A botmaster can use botnets to perform malicious activities. In this paper, we report on the development of a platform for analyzing malware and botnets.


Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.


  1. 1.
    Abu Rajab, M., Zarfoss, J., Monrose, F., Terzis, A.: A multifaceted approach to understanding the botnet phenomenon. In: IMC 2006: Proceedings of the 6th ACM SIGCOMM Conference on Internet Measurement, pp. 41–52. ACM, New York (2006)Google Scholar
  2. 2.
    Alata, E., Alberdi, I., Nicomette, V., Owezarski, P., Kaaniche, M.: Internet attacks monitoring with dynamic connection redirection mechanisms. Journal on Internet Computer Virology 7(2) (2008)Google Scholar
  3. 3.
    Anirudh Ramachandran, D.D., Feamster, N.: Revealing botnet membership using dnsbl counter-intelligence. In: U. Association, editor SRUTI 2006: 2nd Workshop on Steps to Reducing Unwanted Traffic on the Internet, pp. 49–54 (2006)Google Scholar
  4. 4.
    Berger-Sabbatel, G., Korczyński, M., Duda, A.: Architecture of a Platform for Malware Analysis and Confinement. In: Proc. MCSS 2010: Multimedia Communications, Services and Security, Cracow (2010)Google Scholar
  5. 5.
    Kumar, A., Paxson, V., Weaver, N.: Exploiting underlying structure for detailed reconstruction of an internet-scale event. In: PROC. ACM IMC (2005)Google Scholar
  6. 6.
    Trinius, P., Willems, C., Holz, T., Rieck, K.: A malware instruction set for behavior-based analysis. Technical Report 2009-007, University of Mannheim (December 2009)Google Scholar

Copyright information

© Springer-Verlag Berlin Heidelberg 2011

Authors and Affiliations

  • Gilles Berger-Sabbatel
    • 1
  • Andrzej Duda
    • 1
  1. 1.CNRS Grenoble Informatics Laboratory UMR 5217Grenoble Institute of TechnologySaint Martin d’Hères CedexFrance

Personalised recommendations