Conference Proceedings
Detecting Bots Based on Keylogging Activities
Yousof Al-Hammadi, Uwe Aickelin
Proceedings of the 3rd International Conference on Availability, Reliability and Security (ARES2008), Barcelona, Spain | IEEE Computer Society | Published : 2008
DOI: 10.1109/ARES.2008.58
Abstract
A bot is a piece of software that is usually installed on an infected machine without the user's knowledge. A bot is controlled remotely by the attacker under a Command and Control structure. Recent statistics show that bots represent one of the fastest growing threats to our network by performing malicious activities such as email spamming or keylogging. However, few bot detection techniques have been developed to date. In this paper, we investigate a behavioural algorithm to detect a single bot that uses keylogging activity. Our approach involves the use of function calls analysis for the detection of the bot with a keylogging component. Correlation of the frequency of function calls made ..
View full abstract