Detecting Domain Flux Through Patterns of Domain Names' Alphanumeric Characters and Querying Behavior of Hosts[J]. 2013, 47(8): 54-60.
DOI:
Detecting Domain Flux Through Patterns of Domain Names' Alphanumeric Characters and Querying Behavior of Hosts[J]. 2013, 47(8): 54-60.DOI: 10.7652/xjtuxb201308010.
Detecting Domain Flux Through Patterns of Domain Names' Alphanumeric Characters and Querying Behavior of Hosts
The technique of domain flux has been used by many botnets to avoid being blocked by domain blacklists. A new technique is proposed to detect botnets by analyzing the patterns inherent to domains that comprise alphanumeric characters and query behavior of hosts. The method analyzes failed domain queries through support vector machine(SVM)to identify suspicious compromised hosts. Clustering analyses are then performed to generate new successful domains and the groups of hosts that query these domains
and to examine if these host groups are composed of compromised hosts. Then
the command and control(C&C)domains and related IP addresses used by botnets are detected. Experimental results show that the accuracy of SVM prediction reaches more than 98.5% after training
and that the system can accurately detect compromised hosts and IP of C&C servers when DNS traffic from the ISP is monitored.
关键词
Keywords
references
LEDER F, WERNER T. Know your enemy: containing conficker [EB/OL]. [2011-03-05]. http:∥www.honeynet.org/papers/conficker.
ROYAL P. On the kraken and bobax botnets [EB/OL]. [2010-09-10]. http:∥www.damballa.com/downloads/r_pubs/Kraken_Response.pdf.
STONE-GROSS B, COVA M, CAVALLARO L. Your botnet is my botnet:analysis of a botnet takeover [C]∥Proceedings of the 16th ACM Conference on Computer and Communications Security. New York,USA:ACM, 2009:635-647.
YADAV S, REDDY A, REDDY A. Detecting algorithmically generated malicious domain names [C]∥Proceedings of the 10th ACM SIGCOMM Conference on Internet Measurement. New York, USA: ACM, 2010:48-61.
YADAV S, REDDY A. Security and privacy in communication networks [M]. Berlin, Germany: Springer, 2012:446-459.
STALMANS E, IRWIN B. A framework for DNS based detection and mitigation of malware infections on a network [C]∥Proceedings of the IEEE Information Security South Africa. Pretoria, South Africa: ISSA, 2011:1-8.
JIANG N, CAO J, JIN Y. Identifying suspicious activities through DNS failure graph analysis [C]∥Proceedings of the Eighteenth IEEE International Conference on Network Protocols. Kyoto, Japan: ICNP, 2010:144-153.
HAO S, FEAMSTER N, PANDRANGI R. An internet-wide view into DNS lookup patterns [EB/OL]. [2010-06-16]. http:∥www.verisigninc.com/assets/whitepaper-dns-lookup-patterns.pdf.
ANTONAKAKIS M, PERDISCI R, DAGON D. Building a dynamic reputation system for DNS [C]∥The Proceedings of 19th USENIX Security Symposium. Berkeley, California, USA: USENIX Association, 2010:273-289.
ANTONAKAKIS M, PERDISCI R, LEE W. Detecting malware domains at the upper DNS hierarchy [C]∥Proceedings of the 20th USENIX Security Symposium. Berkeley, California, USA: USENIX Association, 2011:27-27.
BILGE L, KIRDA E, KRUEGEL C. Exposure: finding malicious domains using passive DNS analysis [C]∥Proceedings of the 18th Annual Network Distributed System Security Conference. San Diego,USA:NDSS, 2011:1-17.
Alexa Com. The Web information company [EB/OL]. [2008-05-18]. http:∥www.alexa.com/topsites.
LEDER F, WERNER T. Containing conficker tools and infos [EB/OL]. [2011-06-08]. http:∥net.cs.uni-bonn.de/wg/cs/applications/containing-conficker.