TECHNIQUES FOR TARGETED BOTNET PROTECTION USING COLLECTIVE BOTNET ANALYSIS
A botnet identification module identifies members of one or more botnets based upon network traffic destined to one or more servers over time, and provides sets of botnet sources to a traffic monitoring module. Each set of botnet sources includes a plurality of source identifiers of end stations acting as part of a corresponding botnet. A traffic monitoring module receives the sets of botnet sources from the botnet identification module, and upon a receipt of traffic identified as malicious that was sent by a source identified within one of the sets of botnet sources, activates a protection mechanism with regard to all traffic from all of the sources identified by the one of the sets of botnet sources for an amount of time.
1 . A method in a traffic monitoring module (TMM) that is implemented by an electronic device and that is for providing targeted botnet protection for one or more servers, wherein the TMM is deployed in front of the one or more servers in that the TMM receives all network traffic sent by a plurality of end stations that is destined for the one or more servers, the method comprising:
receiving, at the TMM, a message including a plurality of identifiers that have been determined to be used by a subset of the plurality of end stations collectively acting as a suspected botnet, wherein each of the plurality of identifiers is or is based upon a network address;
receiving, at the TMM from a plurality of end stations of the subset of end stations collective acting as the suspected botnet, a plurality of request messages that are destined for a set of one or more of the one or more servers, wherein each of the plurality of request messages includes at least one of the plurality of identifiers in at least a set of one or more locations in the request message; and
responsive to a determination that the plurality of request messages each include, in the set of locations, an identifier that is within the plurality of identifiers and further that these plurality of request messages collectively satisfy a security rule, activating, by the TMM for an amount of time, a protection mechanism that applies to all traffic that has any of the plurality of identifiers in any of the set of locations, wherein none of the plurality of request messages individually would satisfy the security rule.
2 . The method of claim 1 , wherein the security rule, to be satisfied, at least requires a defined amount of request messages that share a common characteristic to be received within a period of time, wherein the defined amount of request messages is greater than one.
3 . The method of claim 2 , wherein the common characteristic is met when each of the plurality of request messages carries a payload representing an attempt to login to an application, wherein the payload includes a password, a username, or both the password and username.
4 . The method of claim 3 , further comprising:
determining that each attempt to login of each of the plurality of request messages was unsuccessful.
5 . The method of claim 4 , wherein said determining that each attempt to login of the plurality of request messages was unsuccessful comprises:
receiving, by the TMM, a plurality of response messages that were originated by the set of servers, wherein each response message indicates that the attempt to login of a corresponding one of the plurality of request messages was unsuccessful.
6 . The method of claim 1 , wherein the set of locations includes one or more of:
a source Internet Protocol (IP) address header field;
a User-Agent header field; and
an X-Forwarded-For header field.
7 . The method of claim 1 , wherein the protection mechanism comprises dropping all traffic that has any of the plurality of identifiers in any of the set of locations regardless of whether it is separately determined to be malicious.
8 . The method of claim 1 , wherein the protection mechanism comprises increasing an amount of security analysis performed with the traffic that has any of the plurality of identifiers in any of the set of locations.
9 . The method of claim 1 , wherein the amount of time that the protection mechanism is activated is specific to the suspected botnet and is based upon an average or maximum attack length of time determined based upon previous activity of the suspected botnet.
10 . The method of claim 1 , wherein the amount of time is indefinite in that it continues until a condition is satisfied, wherein the condition is satisfied upon a determination, by the TMM, that no request messages have been received at the TMM that include any of the plurality of identifiers in any of the set of locations for a threshold amount of time.
11 . A non-transitory computer readable storage medium having instructions which, when executed by one or more processors of an electronic device, cause the electronic device to implement a traffic monitoring module (TMM) that is to perform operations for providing targeted botnet protection for one or more servers, wherein the TMM is to be deployed in front of the one or more servers in that the TMM receives all network traffic sent by a plurality of end stations that is destined for the one or more servers, the operations comprising:
receiving a message including a plurality of identifiers that have been determined to be used by a subset of the plurality of end stations collectively acting as a suspected botnet, wherein each of the plurality of identifiers is or is based upon a network address;
receiving, from a plurality of end stations of the subset of end stations collective acting as the suspected botnet, a plurality of request messages that are destined for a set of one or more of the one or more servers, wherein each of the plurality of request messages includes at least one of the plurality of identifiers in at least a set of one or more locations in the request message; and
responsive to a determination that the plurality of request messages each include, in the set of locations, an identifier that is within the plurality of identifiers and further that these plurality of request messages collectively satisfy a security rule, activating, for an amount of time, a protection mechanism that applies to all traffic that has any of the plurality of identifiers in any of the set of locations, wherein none of the plurality of request messages individually would satisfy the security rule.
12 . The non-transitory computer readable storage medium of claim 11 , wherein the security rule, to be satisfied, at least requires a defined amount of request messages that share a common characteristic to be received within a period of time, wherein the defined amount of request messages is greater than one.
13 . The non-transitory computer readable storage medium of claim 12 , wherein the common characteristic is met when each of the plurality of request messages carries a payload representing an attempt to login to an application, wherein the payload includes a password, a username, or both the password and username.
14 . The non-transitory computer readable storage medium of claim 13 , wherein the operations further comprise:
determining that each attempt to login of each of the plurality of request messages was unsuccessful.
15 . The non-transitory computer readable storage medium of claim 14 , wherein said determining that each attempt to login of the plurality of request messages was unsuccessful comprises:
receiving a plurality of response messages that were originated by the set of servers, wherein each response message indicates that the attempt to login of a corresponding one of the plurality of request messages was unsuccessful.
16 . An electronic device to implement a traffic monitoring module (TMM) that is to perform operations for providing targeted botnet protection for one or more servers, wherein the TMM is to be deployed in front of the one or more servers in that the TMM receives all network traffic sent by a plurality of end stations that is destined for the one or more servers, the electronic device comprising:
one or more processors; and
a non-transitory computer readable storage medium having instructions which, when executed by the one or more processors, cause the electronic device to implement the TMM to:
receive a message including a plurality of identifiers that have been determined to be used by a subset of the plurality of end stations collectively acting as a suspected botnet, wherein each of the plurality of identifiers is or is based upon a network address;
receive, from a plurality of end stations of the subset of end stations collective acting as the suspected botnet, a plurality of request messages that are destined for a set of one or more of the one or more servers, wherein each of the plurality of request messages includes at least one of the plurality of identifiers in at least a set of one or more locations in the request message; and
responsive to a determination that the plurality of request messages each include, in the set of locations, an identifier that is within the plurality of identifiers and further that these plurality of request messages collectively satisfy a security rule, activate, for an amount of time, a protection mechanism that applies to all traffic that has any of the plurality of identifiers in any of the set of locations, wherein none of the plurality of request messages individually would satisfy the security rule.
17 . The electronic device of claim 16 , wherein the security rule, to be satisfied, at least requires a defined amount of request messages that share a common characteristic to be received within a period of time, wherein the defined amount of request messages is greater than one.
18 . The electronic device of claim 17 , wherein the common characteristic is met when each of the plurality of request messages carries a payload representing an attempt to login to an application, wherein the payload includes a password, a username, or both the password and username.
19 . The electronic device of claim 18 , wherein the operations further comprise:
determining that each attempt to login of each of the plurality of request messages was unsuccessful.
20 . The electronic device of claim 19 , wherein said determining that each attempt to login of the plurality of request messages was unsuccessful comprises:
receiving a plurality of response messages that were originated by the set of servers, wherein each response message indicates that the attempt to login of a corresponding one of the plurality of request messages was unsuccessful.