• ثبت نام
    • ورود به سامانه
    مشاهده مورد 
    •   صفحهٔ اصلی
    • نشریات انگلیسی
    • Scientia Iranica
    • Volume 22, Issue 6
    • مشاهده مورد
    •   صفحهٔ اصلی
    • نشریات انگلیسی
    • Scientia Iranica
    • Volume 22, Issue 6
    • مشاهده مورد
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    Detection of Fast-Flux Botnets Through DNS Traffic Analysis

    (ندگان)پدیدآور
    Soltanaghaei, ElaheKharrazi, Mehdi
    Thumbnail
    دریافت مدرک مشاهده
    FullText
    اندازه فایل: 
    2.755 مگابایت
    نوع فايل (MIME): 
    PDF
    نوع مدرک
    Text
    زبان مدرک
    English
    نمایش کامل رکورد
    چکیده
    Botnets are networks build up of a large number of bot computers which provide the attacker with massive resources such as bandwidth, storage, and processing power. In turn allowing the attacker to launch massive attacks such as Distributed Denial of Service (DoS) attacks, or undertake spamming or phishing campaigns. One of the main approaches for botnet detection is based on monitoring and analyzing DNS query/responses in the network, where botnets make their detection more difficult by using techniques such as fast-fluxing. Moreover, the main challenge in detecting fast-flux botnets arises from their similar behavior with that of legitimate networks, such as CDNs, which employ a round-robin DNS technique. In this paper, we propose a new system to detect fastflux botnets by passive DNS monitoring. The proposed system first filters out domains seen in historical DNS traces assuming that they are benign. We believe this assumption to be valid as benign domains usually have longer life time when compared to botnet domains, which are usually short lived. Hence CDN domains which are the main cause of miss-classification, when looking for malicious fast-flux domains, are removed. Afterwards, a few simple features are calculated to help in properly categorizing the domains in question as either benign or botnet related. The proposed system is evaluated by employing DNS traces from our campus network and encouraging evaluation results are obtained.
    کلید واژگان
    botnets
    BOT
    C&C channel
    fast-flux
    IPflux
    DNS server

    شماره نشریه
    6
    تاریخ نشر
    2015-12-01
    1394-09-10
    ناشر
    Sharif University of Technology
    سازمان پدید آورنده
    Department of Computer Engineering, Sharif University of Technology, Tehran, Iran
    Department of Computer Engineering, room 609, Sharif University of Technology, Tehran, Iran

    شاپا
    1026-3098
    2345-3605
    URI
    http://scientiairanica.sharif.edu/article_3790.html
    https://iranjournals.nlai.ir/handle/123456789/119688

    مرور

    همه جای سامانهپایگاه‌ها و مجموعه‌ها بر اساس تاریخ انتشارپدیدآورانعناوینموضوع‌‌هااین مجموعه بر اساس تاریخ انتشارپدیدآورانعناوینموضوع‌‌ها

    حساب من

    ورود به سامانهثبت نام

    آمار

    مشاهده آمار استفاده

    تازه ترین ها

    تازه ترین مدارک
    © کليه حقوق اين سامانه برای سازمان اسناد و کتابخانه ملی ایران محفوظ است
    تماس با ما | ارسال بازخورد
    قدرت یافته توسطسیناوب