<?xml version="1.0" encoding="utf-8"?>
<publication xmlns="http://pi4.informatik.uni-mannheim.de"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:php="http://php.net/xsl"
xsi:noNamespaceSchemaLocation="http://www.informatik.uni-mannheim.de/pi4.data/templates/schema/publication.xsd"
active="true" type="conference" lang="en" toappear="false"
pdf="true" ps="false" txt="false">
  <contributor personID="steiner" />
  <author>Thorsten Holz</author>
  <author personID="steiner" />
  <author>Frederic Dahl</author>
  <author>Ernst W. Biersack</author>
  <author>Felix Freiling</author>
  <title>Measurements and Mitigation of Peer-to-Peer-based Botnets:
  A Case Study on Storm Worm</title>
  <conference>
    <name>LEET: First USENIX Workshop on Large-Scale Exploits and
    Emergent Threats</name>
    <publisher></publisher>
    <booktitle>LEET: First USENIX Workshop on Large-Scale Exploits
    and Emergent Threats</booktitle>
    <organization></organization>
    <location>San Francisco, CA</location>
  </conference>
  <year>2008</year>
  <month>04</month>
  <abstract lang="en">Botnets, i.e., networks of compromised
  machines under a common control infrastructure, are commonly
  controlled by an attacker with the help of a central server: all
  compromised machines connect to the central server and wait for
  commands. However, the first botnets that use peer-to-peer
  networks for remote control of the compromised machines appeared
  in the wild recently. In this paper, we introduce a methodology
  to analyze and mitigate peer-to-peer botnets. In a case study, we
  examine in detail the Storm Worm botnet, the most wide-spread
  peer-to-peer botnet currently propagating in the wild. We were
  able to infiltrate and analyze in-depth the botnet, which allows
  us to estimate the total number of compromised machines.
  Furthermore, we present two different ways to disrupt the
  communication channel between controller and compromised machines
  in order to mitigate the botnet and evaluate the effectiveness of
  these mechanisms.</abstract>
</publication>
