Anglia Ruskin Research Online (ARRO)
Browse
Use of Netflow-IPFix Botnet Detection Tools to Determine Placement for Autonomous VMs.pdf (605.23 kB)

Use of NetFlow/IPFIX Botnet Detection Tools to Determine Placement for Autonomous VMs

Download (605.23 kB)
conference contribution
posted on 2023-07-26, 13:49 authored by Razvan-Ioan Dinita, Adrian Winckles, George Wilson
This paper describes a novel method of autonomously detecting malicious Botnet behaviour within a Cloud datacentre, while at the same time managing Virtual Machine (VM) placement in accordance to its findings, and it presents its implementation with the Scala programming language. A key feature of this method, using output from NetFlow/IPFIX, both of which are capable of producing detailed network traffic logs, is its capability of detecting unusual Client behaviour through the analysis of individual data packet information. It has been implemented as a module of an Autonomous Management Distributed System (AMDS) presented in [Dinita, R. I. et al., 2013], giving it direct access to all the VMs and Hypervisors on the Cloud network. Another key feature is that it can have an immediate and effective impact on network security in a Botnet attack context by issuing lockout commands to every networked VM through the AMDS. It possesses the ability to intelligently control VMWare vSphere local instances based on analysis of collected data and predefined parameters. vSphere in turn, once it receives commands from the AMDS, proceeds to issue instructions to multiple locally monitored ESXi severs in order to ensure continuous security. A proof of concept has been developed and is currently running successfully on the authors’ test bed.

History

Page range

35

Publisher

Canterbury Christ Church University

Place of publication

Canterbury, UK

ISBN

97801909067158

Conference proceeding

CFET 2014 - 7th International Conference on Cybercrime Forensics Education & Training: Conference Programme & Abstracts

Name of event

7th International Conference on Cybercrime Forensics Education and Training (CFET 2014)

Location

Canterbury, UK

Event start date

2014-07-10

Event finish date

2014-07-11

File version

  • Published version

Language

  • eng

Legacy posted date

2016-07-08

Legacy creation date

2019-05-22

Legacy Faculty/School/Department

ARCHIVED Faculty of Science & Technology (until September 2018)

Usage metrics

    ARU Outputs

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC