The Advanced Callback Detection framework also uses a deterministic botnet detection approach, targeted toward detection of known bots. As mentioned earlier, a bot lifecycle can be divided into exploitation, infection and the attack/propagation phases. Each phase has a corresponding attack signature to detect the phase. The framework monitors per source IP address the specified sequence of these attack IDs within a specified time to trigger a correlated attack. This provides a precise bot detection.
Consider the example of Kraken botnet. Kraken bot is known to have the following phases:
Connectivity test to mx.google.com.
Download Test: Front pages of popular news websites – www.nytimes.com, www.cbsnews.com, www.cnn.com, and www.google.com.
Peer Lookup: DNS Queries for randomly generated URI based on dynamic DNS domains.
Peer Connect & Update: Connect to peer bot (UDP dport 447/TCP dport 80/TCP dport 443) and download update.
Download Payload (Spam template, Spam Payload, MX server addresses and so on).
Send Spam.
Phases 1 and 2 are not malicious by themselves. However, when correlated with phases, 3,4,5 and 6, Kraken botnet can be detected effectively.