The Advanced Callback Detection framework uses a probabilistic 0-day botnet detection approach, targeted toward detection of 0-day bots. It consists of multiple heuristics identified during the research and analysis of various bots. Heuristics cover a wide range of checks such as the following:
Anomalies in protocols being used for communication such as HTTP and SSL
Response errors in protocols such as DNS, SMTP
Suspicious behavior such as port scan and stealth scan
Cloud based detection such as GTI File Reputation and IP Reputation
The Advanced Callback Detection framework monitors for such heuristics being exhibited by a particular source IP address within a specified amount of time. This allows the framework to determine if the source IP address has been compromised and is exhibiting bot behavior.
The framework has capabilities to correlate attacks across different communication protocols.
The following are some of the currently implemented heuristics:
SSL: Invalid SSL Flow DetectedSSL: Invalid SSL Flow Detected Due to Wrong Hello Record TypeSSL: Invalid SSL Flow Detected Due to wrong Record VersionSSL: Invalid SSL Flow Detected Due to Wrong Handshake TypeHeuristic DNS: Too Many Type A Query Response Errors FoundHeuristic DNS: Too Many Type MX Query Response Errors FoundDNS: Recursive Query To Root Servers FoundBOT Heuristic: Spam Bot Activity - Multiple Block list Responses from SMTP serverBOT Heuristic: Potential Bot Activity - Multiple Resets from SMTP receiverHeuristic SMTP: Multiple Emails sent without AuthenticationIRC: IRC Client Activity DetectedHTTP: Executable Files Found in Zip FilesHTTP: Password Protected Zip File FoundHTTP: Invalid Flow DetectedBot: Potential Stealth Scanner DetectedMalware: Potential Malicious File Transfer Detected by GTI File Reputation (Artemis)BOT: HTran Connection Bouncer Error Message Detected