Botnet and Malware Detection and Prevention: Development, Deployment, and Research

      Botnet(殭屍網路)與Malware(惡意軟體)目前正高度地困擾著網路使用者,如透過Botnet發送成千上萬封的垃圾郵件、藉由Malware竊取帳號資料...等等。倘若政府機關部門受到Botnet與Malware的入侵,其所造成的損失將難以估計。為了找出因應之道,此計畫規劃以三年的時間循序漸進地 (Beta Trial, Deployment, Research),研究出一系列針對Botnet及Malware的偵測、通報、清除以及預防技術,並實際地與業界產品相互結合,進而達成部署各系統至各大校園網路。

      在第一年裡,我們將邀請目前業界具有解決Botnet/Malware問題能力的產品,進行一次的公開測試活動,藉由此次測試可以深入了解業界目前所使用的方法及其技術上的缺點,未來可以此為依據進行Botnet/Malware解決方案的研究與開發。除此之外我們也將建立測試網路平台(Beta Site),讓研發過程中的系統雛型可以有真實的測試環境以利系統之除錯與改良,在測試平台上亦實際地部署業界產品來觀察使用成效,作為未來研發方向的參考。在第一年的兩大工作項目中,交大網路測試中心(NBL)具有豐富的經驗及成效,因此我們計劃與NBL合作來達成最佳效益。在第二年裡,我們將開始著手研發Botnet/Malware解決方案之相關技術,其中包括了: 偵測、通報、清除以及預防四大重點。由於開發產品並非學術界之專精,因此這方面會積極地與業界廠商建立雙方共同研發產品的合作模式,讓學界人員主導技術研究、業界人員主導產品開發。本年度的另一項任務是會與區網中心的連線單位或其它區網中心合作,部署Botnet/Malware解決方案、擴大使用比率。在第三年裡,工作重點依舊是Botnet/Malware解決方案之相關技術研發,經過前一年將Botnet/Malware解決方案部署在各大網路中,必定會有許多的問題發現,而本年度的工作就是要改善這些問題。同時,將Botnet/Malware解決方案擴展到更多的學術網路及研究網路上使用。

      Botnet (zombie networks) and Malware (malicious software) is now a high degree of distress to many internetworking users.  This is mainly because we could often hear (find) that  spammers  send thousands of  spam messages to organizations via botnet hosts,  that  hackers steal lots of personal information (for authentication) using malware, and so on . Especially, if the government sector is infected by the botnet invasion and/or malware, it would be a disaster and difficult to assess the damage caused. Therefore, in this proposal, we would like to initiate a gradual and orderly, three-year research project (i.e., beta trial, deployment, re-search) to come up with a series of solutions and preventive measures against Malware and Botnet via techniques such as detection, reporting, cleanup, etc.
      In the first year, we will first invite security vendors to provide products capable of dealing with Botnet/Malware issues and to conduct a public evaluation of vendor products. By this evaluation, we could have a better understanding on the state-of-the-art operating principles of the industry's products and try to find out the technical shortcomings of each vendor product. In addition, we will also establish a network test platform (Beta Site), so that we could have a real test environment to facilitate system debugging and development on the prototype systems. On the other hand, in the beta site, we would also deploy the vendor s’ products to observe the effectiveness of them and collect reference information for guiding future research. By considering these, the Network Benchmarking Laboratory (NBL) at National Chiao Tung University has a wealth of experience and effectiveness on the two previously mentioned major tasks, and we plan to cooperate with the NBL to achieve the best efficiency. In the second year, we will begin conducting researches and development on the related technologies, including the four major types: detection, reporting, cleanup, as well as the prevention measures. Since most academic people are usually not good on the development of the products (as compared to the industry people), we will actively co-work with the security industry developers to establish a mutual cooperation model in product research and development. While we academic people focus on leading the technology research, the industry people take the lead on product development. Next, another important of task this year is that we will co-work with local connecting sites of the Hsinchu-Miaoli Regional Center (HCRC) and/or other Regional Center of TANet to further expand the deployment of the anti-botnet systems. Next, after collecting the previous year experience’s deployment of the Botnet / Malware solutions, the focus of the third year lies in the fact that there must be many real problems about using the systems, and we are supposed to work out solutions to fix and/or keep improving them. Also, we would like to further help deploy the Botnet / Malware solutions to more academic and research sites.