MONDEO: Multistage Botnet Detection

08/31/2023
by   Duarte Dias, et al.
0

Mobile devices have widespread to become the most used piece of technology. Due to their characteristics, they have become major targets for botnet-related malware. FluBot is one example of botnet malware that infects mobile devices. In particular, FluBot is a DNS-based botnet that uses Domain Generation Algorithms (DGA) to establish communication with the Command and Control Server (C2). MONDEO is a multistage mechanism with a flexible design to detect DNS-based botnet malware. MONDEO is lightweight and can be deployed without requiring the deployment of software, agents, or configuration in mobile devices, allowing easy integration in core networks. MONDEO comprises four detection stages: Blacklisting/Whitelisting, Query rate analysis, DGA analysis, and Machine learning evaluation. It was created with the goal of processing streams of packets to identify attacks with high efficiency, in the distinct phases. MONDEO was tested against several datasets to measure its efficiency and performance, being able to achieve high performance with RandomForest classifiers. The implementation is available at github.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/09/2018

Malware detection techniques for mobile devices

Mobile devices have become very popular nowadays, due to its portability...
research
02/12/2018

Personal Mobile Malware Guard PMMG: a mobile malware detection technique based on user's preferences

Mobile malware has increased rapidly last 10 years. This rapid increase ...
research
06/27/2019

A New Malware Detection System Using a High Performance-ELM method

A vital element of a cyberspace infrastructure is cybersecurity. Many pr...
research
10/23/2019

Deep learning guided Android malware and anomaly detection

In the past decade, the cyber-crime related to mobile devices has increa...
research
03/15/2019

Grid Computing Model for Mobile: A Better Mobile Grid Computing Model

Grid Computing is an idea of a new kind of network technology in which r...
research
08/13/2022

Analysis and implementation of the SNOW 3G generator used in 4G/LTE systems

The fourth generation of cell phones, marketed as 4G/LTE (Long-Term Evol...
research
11/10/2020

SeqMobile: A Sequence Based Efficient Android Malware Detection System Using RNN on Mobile Devices

With the proliferation of Android malware, the demand for an effective a...

Please sign up or login with your details

Forgot password? Click here to reset