Comparison of the mean-field approach and simulation in a peer-to-peer botnet case study

    Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

    16 Citations (Scopus)
    43 Downloads (Pure)

    Abstract

    Peer-to-peer botnets, as exemplified by the Storm Worm and Stuxnet, are a relatively new threat to security on the internet: infected computers automatically search for other computers to be infected, thus spreading the infection rapidly. In a recent paper, such botnets have been modeled using Stochastic Activity Networks, allowing the use of discrete-event simulation to judge strategies for combating their spread. In the present paper, we develop a mean-field model for analyzing botnet behavior and compare it with simulations obtained from the Möbius tool. We show that the mean-field approach provides accurate and orders-of- magnitude faster computation, thus providing very useful insight in spread characteristics and the effectiveness of countermeasures.
    Original languageEnglish
    Title of host publicationProceedings of the 8th European Performance Engineering Workshop, EPEW 2011
    EditorsN. Thomas
    Place of PublicationLondon
    PublisherSpringer
    Pages133-147
    Number of pages15
    DOIs
    Publication statusPublished - Oct 2011
    Event8th European Performance Engineering Workshop, EPEW 2011 - Borrowdale, United Kingdom
    Duration: 12 Oct 201113 Oct 2011
    Conference number: 8

    Publication series

    NameLecture Notes in Computer Science
    PublisherSpringer Verlag
    Volume6977
    ISSN (Print)0302-9743
    ISSN (Electronic)1611-3349

    Conference

    Conference8th European Performance Engineering Workshop, EPEW 2011
    Abbreviated titleEPEW
    Country/TerritoryUnited Kingdom
    CityBorrowdale
    Period12/10/1113/10/11

    Keywords

    • peer-to-peer botnet spread
    • Mean-field approximation
    • differential equations
    • Simulation

    Fingerprint

    Dive into the research topics of 'Comparison of the mean-field approach and simulation in a peer-to-peer botnet case study'. Together they form a unique fingerprint.

    Cite this