西北工业大学计算机学院,西安,710029
网络首发:2013-08-10,
纸质出版:2013
移动端阅览
张永斌, 陆寅, 张艳宁. 域名请求行为特征与构成特征相结合的域名变换检测[J]. 西安交通大学学报, 2013,47(8):54-60.
Detecting Domain Flux Through Patterns of Domain Names' Alphanumeric Characters and Querying Behavior of Hosts[J]. 2013, 47(8): 54-60.
张永斌, 陆寅, 张艳宁. 域名请求行为特征与构成特征相结合的域名变换检测[J]. 西安交通大学学报, 2013,47(8):54-60. DOI: 10.7652/xjtuxb201308010.
Detecting Domain Flux Through Patterns of Domain Names' Alphanumeric Characters and Querying Behavior of Hosts[J]. 2013, 47(8): 54-60. DOI: 10.7652/xjtuxb201308010.
针对僵尸网络为避免域名黑名单封堵而广泛采用域名变换技术的问题
提出一种域名请求行为特征与域名构成特征相结合的僵尸网络检测方法。该方法通过支持向量机(SVM)分类器对网络中主机解析失败的域名进行分析
提取出可疑感染主机; 通过新域名聚类分析
将请求同一组新域名的主机集合作为检测对象
分析请求主机集合是否由可疑感染主机构成
提取出僵尸网络当前使用的域名集合以及命令与控制(Command and Control
C&C)服务器使用的IP地址集合。实验结果表明:训练后SVM分类器可达98.5%以上的准确率; 经对ISP域名服务器监测
系统可准确提取出感染主机和C&C服务器的IP地址。
The technique of domain flux has been used by many botnets to avoid being blocked by domain blacklists. A new technique is proposed to detect botnets by analyzing the patterns inherent to domains that comprise alphanumeric characters and query behavior of hosts. The method analyzes failed domain queries through support vector machine(SVM)to identify suspicious compromised hosts. Clustering analyses are then performed to generate new successful domains and the groups of hosts that query these domains
and to examine if these host groups are composed of compromised hosts. Then
the command and control(C&C)domains and related IP addresses used by botnets are detected. Experimental results show that the accuracy of SVM prediction reaches more than 98.5% after training
and that the system can accurately detect compromised hosts and IP of C&C servers when DNS traffic from the ISP is monitored.
LEDER F, WERNER T. Know your enemy: containing conficker [EB/OL]. [2011-03-05]. http:∥www.honeynet.org/papers/conficker.
ROYAL P. On the kraken and bobax botnets [EB/OL]. [2010-09-10]. http:∥www.damballa.com/downloads/r_pubs/Kraken_Response.pdf.
STONE-GROSS B, COVA M, CAVALLARO L. Your botnet is my botnet:analysis of a botnet takeover [C]∥Proceedings of the 16th ACM Conference on Computer and Communications Security. New York,USA:ACM, 2009:635-647.
YADAV S, REDDY A, REDDY A. Detecting algorithmically generated malicious domain names [C]∥Proceedings of the 10th ACM SIGCOMM Conference on Internet Measurement. New York, USA: ACM, 2010:48-61.
YADAV S, REDDY A. Security and privacy in communication networks [M]. Berlin, Germany: Springer, 2012:446-459.
STALMANS E, IRWIN B. A framework for DNS based detection and mitigation of malware infections on a network [C]∥Proceedings of the IEEE Information Security South Africa. Pretoria, South Africa: ISSA, 2011:1-8.
JIANG N, CAO J, JIN Y. Identifying suspicious activities through DNS failure graph analysis [C]∥Proceedings of the Eighteenth IEEE International Conference on Network Protocols. Kyoto, Japan: ICNP, 2010:144-153.
HAO S, FEAMSTER N, PANDRANGI R. An internet-wide view into DNS lookup patterns [EB/OL]. [2010-06-16]. http:∥www.verisigninc.com/assets/whitepaper-dns-lookup-patterns.pdf.
ANTONAKAKIS M, PERDISCI R, DAGON D. Building a dynamic reputation system for DNS [C]∥The Proceedings of 19th USENIX Security Symposium. Berkeley, California, USA: USENIX Association, 2010:273-289.
ANTONAKAKIS M, PERDISCI R, LEE W. Detecting malware domains at the upper DNS hierarchy [C]∥Proceedings of the 20th USENIX Security Symposium. Berkeley, California, USA: USENIX Association, 2011:27-27.
BILGE L, KIRDA E, KRUEGEL C. Exposure: finding malicious domains using passive DNS analysis [C]∥Proceedings of the 18th Annual Network Distributed System Security Conference. San Diego,USA:NDSS, 2011:1-17.
Alexa Com. The Web information company [EB/OL]. [2008-05-18]. http:∥www.alexa.com/topsites.
LEDER F, WERNER T. Containing conficker tools and infos [EB/OL]. [2011-06-08]. http:∥net.cs.uni-bonn.de/wg/cs/applications/containing-conficker.
脱立恒,倪宏,刘学. 一种网络冗余流量消除算法. 2013, 47(4):22-27. [doi:10.7652/xjtuxb201304005]
夏秦,王志文,卢柯. 入侵检测系统利用信息熵检测网络攻击的方法. 2013,47(2):14-19. [doi:10.7652/xjtuxb201302 003]
伍文,孟相如,马志强,等. 模块化动态博弈的网络可生存性态势跟踪方法. 2012,46(12):18-23. [doi:10.7652/xjtuxb 201212004]
杨柳静,秦涛,王晨旭. 应用交互式网络流模型的高速网络异常行为检测与控制方法. 2012, 46(6):58-65.[doi:10.7652/xjtuxb201206011]
夏秦,王志文,刘璐. 基于域名共现行为的僵尸网络行为追踪. 2012,46(4):7-12. [doi:10.7652/xjtuxb201204002]
胡鹤,胡昌振,姚淑萍. 应用部分马尔科夫博弈的网络安全主动响应决策模型. 2011,45(4):18-24.[doi:10.7652/xjtuxb201104004]
0
浏览量
4
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621