Faktor Exacta
Vol 12, No 2 (2019)

Menelaah Lalu Lintas Jaringan Internet Relay Chat (IRC) Yang Berbahaya guna Identifikasi Komunikasi Botnet “Plague”

Suryo Bramasto (Program Studi Informatika, Institut Teknologi Indonesia)



Article Info

Publish Date
30 Jul 2019

Abstract

The research presented in this article aims to identify “plague” botnet communication pattern, with the aid of Wireshark Packet Analyzer as proof of concept (PoC) towards unique communication pattern analysis between infected host and botnet. The research is conducted on public IRC (Internet Relay Chat) network, specifically at the opened domain for botnet research, that is, irc.accesox.net. COMODO Internet Security also used for determining files downloaded by the botnet to identify whether there any malware or not. The observation is done on 60 captured packets, which then the TCP stream excerpt and the protocols hierarchy statistic from those packets being analyzed. Based on the analysis of TCP stream excerpt and the protocols hierarchy statistic, the communication pattern between bot, botmaster, and infected host are known. Wireshark could show the data inside the TCP stream excerpt and all captured protocols. The conducted analysis on TCP stream excerpt and protocols hierarchy statistic is based on RFC 2812 (Internet Relay Chat: Client Protocol – IETF Tools). The analysis on TCP stream excerpt and protocols hierarchy statistic yield botnet activity information for the next step of the analysis of botnet attack, which is dataset and prediction model building. The prediction model can then be implemented to predict whether network traffic is safe or harmful.       Keywords: botnet, COMODO internet security, Internet Relay Chat (IRC), RFC 2812, Wireshark

Copyrights © 2019






Journal Info

Abbrev

Faktor_Exacta

Publisher

Subject

Civil Engineering, Building, Construction & Architecture Computer Science & IT Control & Systems Engineering Electrical & Electronics Engineering Industrial & Manufacturing Engineering

Description

Faktor Exacta is a peer review journal in the field of informatics. This journal was published in March (March, June, September, December) by Institute for Research and Community Service, University of Indraprasta PGRI, Indonesia. All newspapers will be read blind. Accepted papers will be available ...