Botnet activities can't be tracked entirely with traditional methods because of the deficiency of information in local behavioral feature. A novel approach on tracking Botnet activity is presented based on co-occurrence relation of domain name system(DNS)queries. An algorithm is utilized to calculate the co-occurrence between undetermined DNS and known Botnet DNS so as to find some other Botnet DNS. Three improved measures are proposed in order to increase the accuracy of evaluating co-occurrence. The three measures are filtering DNS access by network address translation
differentiating individual spatial Botnet and observation time based statistic of co-occurrence. Experiments are carried out with test data of DNS queries collected in the campus network of Xi'an Jiaotong University. The results show that some advantages are acquired obviously with the improved measures
such as the number of undetermined DNS can fall to a quarter of traditional method
the co-occurrence acquired is more suitable for the top ten DNS and the accuracy is improved in finding zombies.
关键词
Keywords
references
KONRAD R, GUIDO S, TOBIAS L, et al. Detecting the phoning home of malicious software [C]∥Proceeding of the 2010 Symposium on Applied Computing. Los Alamitor, CA, USA: IEEE Computer Society, 2010:298-304.
PETER W, LEYLA B, THORSTEN H, et al. Automatically generating models for Botnet detection[C]∥Proceeding of Symposium on Research in Computer Security. Los Alamitos, CA, USA: IEEE Computer Society, 2009:104-110.
MCCUSKER O, KIAYIAS A, WALLUCK D, et al. A combined fusion and mining strategy for detecting Botnets [J]. International Journal of Information Security, 2009, 8(11):71-82.
HE Yuanchen, ZHONG Zhenyu, TANG Yuchun. Mining DNS for malicious domain registrations [J]. Journal of the ACM, 2010, 12(32):335-348.
HU Xin, SHEN Tao. Measurement and analysis of global IP-usage patterns of Botnets [J]. Chinese Journal of Computers, 2011, 34(2): 207-214.
VILLAMAR R, BRUSTOLONI J C. Identifying Botnets using anomaly detection techniques applied to DNS traffic [C]∥Proceeding of the 5th IEEE Consumer Communications and Networking Conference. Los Alamitos, CA, USA: IEEE Computer Society, 2008:476-481.
SATO K, ISHIBASHI K. Extending black domain name list by using co-occurrence relation between DNS queries [C]∥ Proceeding of the 2010 USENIX Workshop on Large-Scale Exploits and Emergent Threats. Los Alamitor, CA, USA: IEEE Computer Society, 2010:2011-2020.