Incollection

Peer-to-Peer Botnet Investigation: A Review

Mark Scanlon; M-Tahar Kechadi

Mark Scanlon; M-Tahar Kechadi. Proceedings of the 6th International Symposium on Digital Forensics and Information Security (DFIS-2012), Future Information Technology, Application, and Service, pp. 231-238, 2012.

Contribution Summary

This paper provides a comprehensive review of peer-to-peer (P2P) botnet investigation, a crucial aspect of digital forensics and cybersecurity. P2P botnets have become a significant threat due to their decentralized nature, making them difficult to detect and investigate. The authors outline the state-of-the-art in P2P botnet investigation, including the challenges and obstacles faced by investigators, such as dynamic host configuration protocol, proxy servers, and encrypted communication. The paper also presents case studies of notable P2P botnets, including Nugache, Storm Worm, and Waledec, highlighting their unique characteristics and vulnerabilities. By combining research, network monitoring, and network crawling, investigators can successfully detect and monitor P2P botnets, despite their complexities.

Keywords: Peer-to-Peer Botnets; Digital Forensics; Cybersecurity; Botnet Investigation; P2P Network Analysis; Malware Analysis; Network Security

Abstract

Botnets have become the tool of choice to conduct a number of online attacks, e.g., distributed denial of service (DDoS), malware distribution, email spamming, phishing, advertisement click fraud, brute-force password attacks, etc. Criminals involved in conducting their craft online all share one common goal; not to get caught. Botnet design, as a result, has moved away from the traditional, more traceable and easily blocked client/server paradigm towards a decentralized Peer-to-Peer (P2P) based communication system. P2P Internet communication technologies lend themselves well to be used in the world of botnet propagation and control due to the level of anonymity they award to the botmaster. For the cybercrime investigator, identifying the perpetrator of these P2P controlled crimes has become significantly more difficult. This paper outlines the state-of-the-art in P2P botnet investigation.

BibTeX

@incollection{scanlon2012p2pbotnetreview,
	title="{Peer-to-Peer Botnet Investigation: A Review}",
	author={Scanlon, Mark and Kechadi, M-Tahar},
	booktitle={Proceedings of the 6th International Symposium on Digital Forensics and Information Security (DFIS-2012), Future Information Technology, Application, and Service},
	pages="231-238",
	month=09,
	year=2012,
	address={Vancouver, Canada},
	publisher={Springer},
  doi={10.1007/978-94-007-5064-7_33},
}