ASP2P: The Next Evolution of "Invisible" Social Peer-to-Peer Botnets
ASP2P: An advanced botnet based on social networks over hybrid P2P
This paper introduces ASP2P, an advanced hybrid peer-to-peer botnet that leverages social networks (e.g., Twitter, Facebook) as Command and Control (C&C) servers. By integrating social media APIs with a hierarchical P2P structure and HTTP-based communication, it achieves superior stealth and resilience against take-down attempts.
TL;DR
Researchers from BUPT have designed ASP2P, a hybrid botnet that hides its command-and-control (C&C) logic inside popular social networks like Facebook and Twitter. By blending social API calls with a peer-to-peer hierarchy, it avoids traditional "bootstrap" vulnerabilities and remains undetected under the guise of regular HTTP traffic.
Problem & Motivation: The Weakness of Static C&C
Most security professionals are adept at taking down centralized botnets by blacklisting C&C server IPs. Even P2P botnets have a "noise" problem—they generate identifiable traffic patterns during peer discovery. The authors identified a gap: Social Networks provide an authentic, high-traffic cover for malicious commands. If a bot looks like it's just browsing a Weibo feed or a Twitter API, it becomes exponentially harder for firewalls to flag it as a threat.
Methodology: The Architecture of Deception
The ASP2P botnet uses a dual-layer strategy to maximize both reach and stealth.
1. Hybrid P2P Topology
Instead of a flat network, the system categorizes bots into two roles:
- Servent Bots: The "supernodes." They have static IPs, high bandwidth, and high CPU power. They fetch instructions from social networks and serve them to the rest of the network.
- Client Bots: These are typically firewalled or dynamic-IP victims. They only talk to Servent bots, never directly to the social network, reducing the "footprint" of the infection.
2. The Promotion Formula
How does a bot become a leader? The paper proposes an Index Factor (IF): This formula ensures that only the most stable and powerful hosts (high online time and bandwidth ) manage the distribution of commands.

3. Encrypted Handshakes
To prevent "botnet hijacking" by researchers, each connection between a Client and a Servent bot starts with a dynamic RSA/MD5 handshake. This ensures that every session key is unique and temporary—making it impossible for defenders to decrypt historic traffic even if they capture a single key.
Experiments & Results
The authors tested ASP2P on PlanetLab, a global research network, to simulate real-world internet conditions.
Unprecedented Stealth
When compared to previous "Partially Decentralized" P2P botnets, ASP2P's efficiency is remarkable. While older botnets would spike a CPU to 55% when handling 60+ connections, ASP2P stays under 4% utilization. This prevents the victim from noticing any slowdown, which is the most common way malware is discovered by end-users.

Extreme Robustness
In robustness simulations, the botnet proved nearly immune to partial take-downs. Even if a defender manages to identify and shut down 70% of the Servent bots, the Client bots can still find alternative paths to receive commands. Total collapse only occurs when nearly 100% of the backbone is eradicated.

Critical Insight & Conclusion
The true innovation of ASP2P isn't just the P2P structure; it's the abuse of trust inherent in Social Network APIs. By using legitimate third-party developer platforms (like Facebook's Graph API), botmasters can "hide in plain sight."
Future Outlook: As botnets evolve, signature-based antivirus will become obsolete. The authors suggest that only anomaly-based detection—looking for subtle, repetitive patterns in HTTP traffic and API calling frequencies—can stop such advanced social-P2P threats.
