4.7 Article

Dissecting SpyEye - Understanding the design of third generation botnets

Journal

COMPUTER NETWORKS
Volume 57, Issue 2, Pages 436-450

Publisher

ELSEVIER
DOI: 10.1016/j.comnet.2012.06.021

Keywords

Botnets; Malware; Malicious Code; Rootkits; Cybercrime

Ask authors/readers for more resources

Botnet malware is improving with the latest (3rd) generation exemplified by the SpyEye and Zeus botnets. These botnets are important to understand because they target online financial transactions, primarily with banks. In this paper, we analyze the components from multiple generations of the SpyEye botnet in order to understand both how it works and how it is evolving. SpyEye is a sophisticated piece of malware with a modular design that eases the incorporation of improvements. We will discuss in detail the complete framework of SpyEye botnet consisting of the Bot Development Kit (BDK), the plugin architecture, the backend storage server, the bot design and the web-based Command and Control (C&C) management system. In addition, we also examine the techniques used by SpyEye to steal money. Crown Copyright (c) 2012 Published by Elsevier B.V. All rights reserved.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.7
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available