|
|
Detection of fast-ux botnets through DNS traffic analysis
|
|
|
|
|
نویسنده
|
Soltanaghaei E. ,Kharrazi M.
|
منبع
|
scientia iranica - 2015 - دوره : 22 - شماره : 6-D2 - صفحه:2389 -2400
|
چکیده
|
Botnets are networks built up of a large number of bot computers, which provide the attacker with massive resources, such as bandwidth, storage, and processing power, in turn, allowing the attacker to launch massive attacks, such as distributed denial of service (ddos) attacks, or undertake spamming or phishing campaigns. one of the main approaches for botnet detection is based on monitoring and analyzing dns query/responses in the network, where botnets make their detection more dicult by using techniques such as fast-uxing. moreover, the main challenge in detecting fast-ux botnets arises from their similar behavior with that of legitimate networks, such as cdns, which employ a roundrobin dns technique. in this paper, we propose a new system to detect fast-ux botnets by passive dns monitoring. the proposed system first filters out domains seen in historical dns traces assuming that they are benign. we believe this assumption to be valid as benign domains usually have long lifetime as compared to botnet domains, which are usually shortlived. hence, cdn domains, which are the main cause of misclassifcation when looking for malicious fast-ux domains, are removed. afterwards, a few simple features are calculated to help in properly categorizing the domains in question as either benign or botnet related. the proposed system is evaluated by employing dns traces from our campus network and encouraging evaluation results are obtained.
|
کلیدواژه
|
Botnets; Bot; C&C channel; Fast-ux; IP-ux ,DNS server.
|
آدرس
|
sharif university of technology, Department of Computer Engineering, ایران, sharif university of technology, Department of Computer Engineering, ایران
|
پست الکترونیکی
|
kharrazi@sharif.edu
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|