A method for analyzing network traffic to measure botnet control scale

By analyzing network traffic to identify botnet commands and control instructions, establishing a feature dataset, recording logs, and calculating the number of compromised computer IPs, the problem of inaccurate botnet size measurement is solved, enabling rapid, comprehensive, and accurate botnet size monitoring and governance.

CN119276526BActive Publication Date: 2025-10-28NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410428938.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-10
Publication Date
2025-10-28
Estimated Expiration
2044-04-10

AI Technical Summary

Technical Problem

Existing technologies lack accurate and efficient methods to measure the control scale of botnets, resulting in the inability to detect and manage large-scale botnets in a timely manner, thus affecting cybersecurity.

Method used

By analyzing network traffic, a dataset of botnet command and control instruction characteristics is established to identify botnet traffic, record command and control logs, monitor botnet communication activities in real time, and calculate the number and growth rate of botnet IPs in various dimensions to accurately measure the size of the botnet.

Benefits of technology

It enables rapid, comprehensive, and accurate measurement of botnet size in specific networks, timely detection and management of large-scale botnets, and improves network security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276526B_ABST
    Figure CN119276526B_ABST
Patent Text Reader

Abstract

This invention relates to a method for analyzing network traffic and measuring the control scale of a botnet. First, it collects samples of discovered botnet programs to establish a dataset of botnet command and control instruction characteristics. By analyzing inbound and outbound network traffic, it identifies and records session information matching the instruction characteristics, recording botnet command and control logs. It then correlates the command and control logs with domain name request logs in network traffic in real time, adding a C2 control domain name field to the command and control logs. Finally, it uses a botnet control scale measurement algorithm to analyze the command and control logs, calculating the cumulative number of communicating botnet IPs and the daily number of communicating botnet IPs for each botnet family, each C2 control domain name, and each C2 IP address, thereby detecting botnets with large or rapidly expanding control scales. This invention accurately identifies botnet traffic from network traffic accessing C2 servers and then calculates the botnet scale, providing more comprehensive coverage and accurate measurement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a method for measuring the size of a botnet in the field of network security technology, and in particular to a method for analyzing network traffic to measure the control size of a botnet. Background Technology

[0002] A botnet is a network that uses one or more propagation methods to infect a large number of networked devices with botnet programs, creating a one-to-many control structure between the attacker and the infected devices. A botnet consists of a botnet master (the attacker), a command and control server (C2), and botnet hosts (the compromised machines). The botnet master issues commands to the botnets through the C2. Currently discovered botnets can be mainly divided into centralized botnets and P2P botnets based on their network topology. In a P2P botnet, each botnet is both a C2 and a compromised machine. Botnets can constitute an attack platform, allowing attackers to launch various attacks, such as DDoS attacks, cryptocurrency mining, data theft, spreading malicious code, and external attacks.

[0003] With increasing networking and informatization, the vast number of networked devices lacking cybersecurity protection on the internet provide attackers with massive attack resources, leading to the continuous emergence of large-scale botnets that severely impact the normal operation of basic networks and critical information systems. For example, the Mirai botnet, discovered in 2016, massively controlled IoT devices globally and used these devices as nodes to launch large-scale DDoS attacks, causing major websites such as Dyn, OVH, GitHub, and Twitter to lose service. The Fodcha botnet, discovered in 2022, could control devices with various architectures and repeatedly attacked our critical information systems. Timely detection and mitigation of large-scale botnets are essential for maintaining the cybersecurity of basic networks and critical information systems.

[0004] Currently, security agencies and related organizations focus on rapidly discovering new types of botnets based on endpoint data and honeypot capture data. However, they lack accurate and efficient methods for measuring the control scale of botnets. They mainly use botnet C2IP address or domain name access volume or endpoint and honeypot infection ratio to estimate the control scale. Due to the large amount of network scanning and detection data and the limited number of endpoint honeypots deployed, existing methods cannot accurately measure the control scale of botnets within a specific network.

[0005] Currently, there is no unified and accurate method for measuring the scale of botnets. The industry mainly uses two methods. Method one involves statistically analyzing the access volume of botnet C2IP addresses or domains, calculating the control scale based on the number of accessing IPs. However, this method is inaccurate. Firstly, many scanning and probing traffic flows across the network, and these accesses to C2IP addresses or domains do not necessarily indicate control. Secondly, other services may be running on the C2IP, meaning that traffic from that IP or domain is not necessarily from botnets. This leads to inaccurate calculations using this method. Method two estimates the control scale based on the number of deployed detection terminals and honeypots, as well as the infection ratio of terminals and honeypots. However, because the number of deployed terminals and honeypots is limited, this estimation is also inaccurate.

[0006] In view of the shortcomings of the existing technology, the inventors, through continuous research, design, and repeated trials and improvements, have finally created this invention with practical value. Summary of the Invention

[0007] The main objective of this invention is to overcome the shortcomings of existing technologies and provide a method for analyzing network traffic and measuring the control scale of botnets. The technical problem to be solved is to quickly, efficiently and accurately measure the control scale of various botnets in a specific network, with a more comprehensive monitoring coverage and more accurate and efficient measurement and analysis. It can be used to support the timely detection of large-scale botnets and rapidly expanding botnets, so as to facilitate subsequent special governance, and is very suitable for practical use.

[0008] The concept of this invention is to accurately identify the traffic of botnets from network traffic accessing C2 servers, thereby calculating the size of the botnet with accurate measurement methods. To this end, this invention first establishes a dataset of botnet command and control instruction characteristics; it then analyzes network traffic to capture and reconstruct botnet command and control instruction data, recording and analyzing botnet command and control logs; finally, it continuously monitors the communication activities of botnets from multiple dimensions, including the addresses of each botnet family, each C2 control domain, and each C2 IP, accurately measuring and tracking the address control scale of each family, each C2 control domain, and each C2 IP.

[0009] The objective of this invention and the technical problem it solves are achieved through the following technical solution. A method for analyzing network traffic and measuring the scale of a botnet, according to this invention, includes the following steps:

[0010] Step 1: Collect exposed and discovered botnet samples, extract network session characteristics of botnet commands and control instructions through reverse engineering of sample code or communication data analysis, and establish a botnet command and control instruction feature dataset;

[0011] Step 2: Obtain network inbound and outbound traffic based on the detection coverage area, and perform in-depth analysis of network inbound and outbound traffic using deep packet inspection technology. Read the content information carried by IP packets and reconstruct it to obtain complete session information.

[0012] Step 3: Match and compare each session information with the botnet command and control instruction feature dataset, identify and record session information that matches the instruction features, and record botnet command and control logs. Botnet command and control logs include communication time, instruction type, botnet IP, botnet communication port, C2IP, C2 control domain name port, botnet family, and communication session data.

[0013] Step 4: Perform real-time correlation between the botnet command and control logs and the domain name request logs in the network inflow and outflow traffic. Analyze the domain name requests of the botnets before they start accessing the C2IP and during the access period. Obtain the domain name with the resolution value of C2IP, which is the C2 control domain name. Add the C2 control domain name field to the botnet command and control logs.

[0014] Step 5: Analyze the command and control logs to calculate the cumulative number of botnet IPs, daily number of botnet IPs, hourly number of botnet IPs, daily growth rate of botnet IPs, and hourly growth rate of botnet IPs for each botnet family, each C2 control domain, and each C2 IP.

[0015] The objectives of this invention and the technical problems it addresses can be further achieved by the following technical measures.

[0016] In the above technical solution, the cumulative number of communication botnet IPs, daily number of communication botnet IPs, hourly number of communication botnet IPs, daily growth rate of communication botnet IPs, and hourly growth rate of communication botnet IPs for each botnet family, each C2 control domain name, and each C2 IP are all used to represent the control scale and changing trend of the botnet. Botnets with large control scale or rapidly expanding control scale can be detected by setting thresholds.

[0017] In the above scheme, step 4 specifically includes the following steps:

[0018] Step 4.1: Set the time threshold for analyzing the period before the botnet accesses the C2IP to Ns, and obtain the botnet domain name access request log from the time the botnet communicates with the C2IP - Ns to the time the botnet communicates with the C2IP.

[0019] Step 4.2: Analyze the domain request logs obtained in Step 4.1 to obtain the domain name with the resolution value C2IP, which is the C2 control domain name;

[0020] Step 4.3: Set the time threshold for analyzing the time period of access to C2IP by botnets to Nt. Add a C2 control domain name field to the logs of the same C2IP in the botnet command and control logs within the time period from the communication time between the botnet and C2IP - Nt to the communication time between the botnet and C2IP + Nt. The control domain name value is the C2 control domain name obtained in step 4.2.

[0021] In the above technical solution, the botnet commands and control instructions are online instructions, heartbeat instructions, and data return instructions sent periodically by the botnet to the C2IP, or attack instructions and operation instructions sent periodically by the C2IP to the botnet.

[0022] In the above technical solution, the cumulative number of communication botnet IPs, the daily number of communication botnet IPs, and the hourly number of communication botnet IPs refer to the number of duplicate botnet IPs in the command and control logs within a specific time range, i.e., the number of different botnet IPs, which are used to represent the scale of the botnet within a specific time range.

[0023] In the above technical solution, the network refers to the networks of various operators, the networks of various subordinate operators, and the internal networks of various large enterprises.

[0024] The above technical solution has at least the following advantages:

[0025] 1. This invention captures and analyzes botnet command and control logs. The log data is accurate and does not retain scanning and probing data. It does not depend on the number of terminals and honeypots deployed. It can comprehensively grasp the activity behavior of each type of botnet in a specific network. Compared with traditional monitoring methods, it has a more comprehensive coverage and more timely and accurate measurement and analysis.

[0026] 2. This invention selects to detect during the command and control phase of the botnet, which can achieve twice the result with half the effort.

[0027] 3. This invention can measure the control scale of all exposed and discovered botnets, and can promptly detect botnets with large or rapidly expanding control scales, thereby improving the effectiveness of botnet governance.

[0028] The specific method of the present invention is given in detail in the following embodiments and accompanying drawings. Attached Figure Description

[0029] Figure 1 This is a flowchart of the process of this invention. Detailed Implementation

[0030] To further illustrate the technical means and effects adopted by the present invention to achieve the intended purpose, the following describes in detail, with reference to the accompanying drawings and preferred embodiments, a method for analyzing network traffic and measuring the scale of botnet control according to the present invention, including its specific implementation, method, steps, features and effects.

[0031] Please see Figure 1 A preferred embodiment of the present invention provides a method for analyzing network traffic and measuring the scale of botnet control, which mainly includes the following steps:

[0032] Step S1: Collect exposed and discovered botnet samples, extract network session features of botnet commands and control instructions through reverse engineering of sample code or communication data analysis, and establish a botnet command and control instruction feature dataset;

[0033] As one embodiment, the botnet commands and control instructions mentioned in step S1 are online instructions, heartbeat instructions, and data return instructions sent periodically by the botnet to the C2IP, or attack instructions and operation instructions sent periodically by the C2IP to the botnet.

[0034] Step S2: Obtain network inbound and outbound traffic based on the detection coverage area, perform in-depth analysis of network inbound and outbound traffic using deep packet inspection technology, and reconstruct the content information carried by IP packets to obtain complete session information.

[0035] As one embodiment, the network described in S2 includes various operator networks, lower-level operator networks, and internal networks of large enterprises.

[0036] Step S3: Match and compare each session information with the botnet command and control instruction feature dataset, identify and record session information that matches the instruction features, and record botnet command and control logs. Botnet command and control logs include communication time, instruction type, botnet IP, botnet communication port, C2IP, C2 control domain name port, botnet family, and communication session data.

[0037] Step S4: Perform real-time correlation between the botnet command and control logs and the domain name request logs in the network inflow and outflow traffic. Analyze the domain name requests made by the botnets before and during the period of access to the C2IP, obtain the domain name with the resolution value of C2IP (i.e., the C2 control domain name), and add a C2 control domain name field to the botnet command and control logs. This includes the following sub-steps:

[0038] Step S4.1: Set the threshold for the period of time before the botnet accesses the C2IP to Ns, and obtain the botnet domain name access request log from the time the botnet communicates with the C2IP - Ns to the time the botnet communicates with the C2IP.

[0039] Step S4.2: Analyze the domain name request log obtained in step S41 to obtain the domain name with the resolution value C2IP, i.e., the C2 control domain name;

[0040] Step S4.3: Set the time threshold for analyzing the time period of access to C2IP by the botnet to Nt. Add the C2 control domain name field to the logs of the same C2IP in the botnet command and control logs within the time period from the communication time between the botnet and C2IP - Nt to the communication time between the botnet and C2IP + Nt. The control domain name value is the C2 control domain name obtained in step S42.

[0041] As one embodiment, in step S4.1, the time threshold Ns is from 1 minute to 1 hour. In this embodiment, it is set to 1 minute. The botnet domain name access request log is obtained from 1 minute before the start of the communication time between the botnet and C2IP to the communication time between the botnet and C2IP.

[0042] As one embodiment, in step S4.3, the time threshold Nt is from 1 minute to 1 day. In this embodiment, it is set to 15 minutes. During the period from 15 minutes before the start of the communication time between the botnet and the C2IP to 15 minutes after the end of the communication time between the botnet and the C2IP, the C2 control domain name field is added to the logs of the same C2IP in the botnet command and control log. The C2 control domain name value is the C2 control domain name obtained in step S4.3.

[0043] Step S5: Analyze the command and control logs to calculate the cumulative number of botnet IPs, daily number of botnet IPs, hourly number of botnet IPs, daily growth rate of botnet IPs, and hourly growth rate of botnet IPs for each botnet family, each C2 control domain, and each C2 IP.

[0044] Among them, the cumulative number of communication botnet IPs, daily number of communication botnet IPs, hourly number of communication botnet IPs, daily growth rate of communication botnet IPs, and hourly growth rate of communication botnet IPs for each botnet family, each C2 control domain, and each C2 IP are used to represent the control scale and changing trend of the botnet. Botnets with large control scale or rapidly expanding control scale are detected by setting thresholds.

[0045] Among them, the cumulative number of communication botnet IPs, the daily number of communication botnet IPs, and the hourly number of communication botnet IPs refer to the number of duplicate botnet IPs in the command and control logs within a specific time range, i.e., the number of different botnet IPs, which are used to represent the scale of the botnet within a specific time range.

[0046] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.

Claims

1. A method for analyzing network traffic to measure the control scale of a botnet, characterized in that: It includes the following steps: Step 1: Collect exposed and discovered botnet samples, extract network session characteristics of botnet commands and control instructions through reverse engineering of sample code or communication data analysis, and establish a botnet command and control instruction feature dataset; Step 2: Obtain network inbound and outbound traffic based on the detection coverage area, and perform in-depth analysis of network inbound and outbound traffic using deep packet inspection technology. Read the content information carried by IP packets and reconstruct it to obtain complete session information. Step 3: Match and compare each session information with the botnet command and control instruction feature dataset, identify and record session information that matches the instruction features, and record botnet command and control logs. Botnet command and control logs include communication time, instruction type, botnet IP, botnet communication port, C2IP, C2 control domain name port, botnet family, and communication session data. Step 4: Perform real-time correlation between the botnet command and control logs and the domain name request logs in the network inflow and outflow traffic. Analyze the domain name requests made by the botnets before and during the period of access to the C2IP, obtain the domain name with the resolution value of C2IP (i.e., the C2 control domain name), and add a C2 control domain name field to the botnet command and control logs; the specific steps are as follows: Step 4.1: Set the time threshold for analyzing the period before the botnet accesses the C2IP to Ns, and obtain the botnet domain name access request log from the time the botnet communicates with the C2IP - Ns to the time the botnet communicates with the C2IP. Step 4.2: Analyze the domain request logs obtained in Step 4.1 to obtain the domain name with the resolution value C2IP, which is the C2 control domain name; Step 4.3: Set the time threshold for analyzing the time period of access to C2IP by botnets to Nt. Add the C2 control domain name field to the logs of the same C2IP in the botnet command and control logs within the time period from the communication time between the botnet and C2IP - Nt to the communication time between the botnet and C2IP + Nt. The value of the botnet control domain name is the C2 control domain name obtained in step 4.

2. Step 5: Analyze the botnet command and control logs to calculate the cumulative number of botnet IPs communicating with each botnet family, each C2 control domain, and each C2 IP, as well as the daily number of botnet IPs communicating with each botnet family, each C2 control domain, and each C2 IP.

2. The method for analyzing network traffic and measuring the scale of botnet control according to claim 1, characterized in that: The cumulative number of botnet IPs, daily number of botnet IPs, hourly number of botnet IPs, daily growth rate of botnet IPs, and hourly growth rate of botnet IPs for each botnet family, each C2 control domain, and each C2 IP are all used to represent the control scale and trend of the botnet. Botnets with large control scale or rapidly expanding control scale are detected by setting thresholds.

3. The method for analyzing network traffic and measuring the scale of botnet control according to claim 1, characterized in that: The botnet commands and control instructions mentioned in step 1 are online commands, heartbeat commands, and data return commands sent periodically by the botnet to the C2IP, or attack commands and operation commands sent periodically by the C2IP to the botnet.

4. The method for analyzing network traffic and measuring the scale of botnet control according to claim 1, characterized in that: The cumulative number of communication botnet IPs, daily number of communication botnet IPs, and hourly number of communication botnet IPs refer to the number of duplicate botnet IPs in the command and control logs within a specific time range, i.e., the number of different botnet IPs, used to represent the scale of the botnet within a specific time range.

5. The method for analyzing network traffic and measuring the scale of botnet control according to claim 1, characterized in that: The networks mentioned include the networks of various operators, the networks of various subordinate operators, and the internal networks of various large enterprises.

Citation Information

Patent Citations

  • Domain name server (DNS) data packet-based bot-net domain name discovery method

    CN102685145A

  • Method and system for detecting botnets based on weblogs

    CN108768917A