This section describes the detection of some popular and well known bots like Aurora, Kraken and Pushdo with heuristics support. Specific traits and techniques implemented by these bots are detected.
Heuristics detected on Aurora and Pushdo bot traffic
The following are observed:
SSL Unix-Timestamp too old or too long into the future (
SSL: Client Hello Invalid Unix Timestamp)Invalid SSL Flow (
SSL: Invalid SSL Flow Detected)
The framework raises a medium confidence heuristic correlation bot alert, BOT: Potential Bot Detected - Medium Confidence Heuristics Correlation.
Heuristics detected on Kraken bot traffic
The following are observed:
SMTP 5xx errors from servers (
SMTP: Unexpected Server Rejection)E-mails sent without authentication (
BOT Heuristic: Potential Bot Activity - Multiple Resets from SMTP receiver)
The framework raises a medium confidence heuristic correlation bot alerts, BOT: Potential Bot Detected - Medium Confidence Heuristics Correlation.
The Advanced Callback Detection framework which consists of all the above listed heuristics has proved effective in detecting the following categories and traits exhibited by bots.
Spam bots (bots designed to assist in sending spam emails)
Domain Flux (bots that implement domain-generation algorithms to generate domains on the fly to stay active and undetected)
IRC bots (bots that use IRC protocol to carry out malicious activities)
HTran (bots that use HTran a connection bouncer to redirect TCP traffic destined for one host to an alternate host to hide the primary C&C server)
Suspicious scan activity (bots that usually scan to look for open ports and services on the system)