CCGA: Clustering and Capturing Group Activities for DGA-based botnets detection

被引:7
|
作者
Liu, Zhicheng [1 ,2 ]
Yun, Xiaochun [1 ,3 ]
Zhang, Yongzheng [1 ,2 ]
Wang, Yipeng [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Coordinat Ctr China, Natl Comp Network Emergency Response Tech Team, Beijing, Peoples R China
关键词
botnet; DNS; group behavior; DGA;
D O I
10.1109/TrustCom/BigDataSE.2019.00027
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnet is a part of the most destructive threats to network security and is often used in malicious activities. DGA-based botnet, which uses Domain Generation Algorithm (DGA) to evade detection, has become the main channel to carry out online crimes. In the past, many detection mechanisms focusing on domain features are proposed, but the potential problem is that the features extracting only from the domain names are insufficient and the enemies could easily forge them to disturb detection. In this paper, we propose a novel approach named CCGA to detect DGA-based botnet by leveraging the concerted group behaviors of infected hosts on DNS traffic. The analysis of group behaviors enhances the robustness of our system irrespective of various evasion techniques, such as fake-querying, packet encryption and noise generated by normal users. The proposed scheme associates hosts together in an unsupervised way and then uses supervised learning to distinguish whether it's a botnet. Our system is evaluated in a large ISP over two days and compared with the state of art FANCI [24]. Experimental results show that CCGA can accurately and effectively detect DGA-based botnet in a real-world network. Our system also catches 5 unknown botnet groups and provides a novel method to verify them. Therefore, the system will provide an unique perspective on the current state of globally distributed malware, particularly the ones that use DNS.
引用
收藏
页码:136 / 143
页数:8
相关论文
共 43 条
  • [21] DGA-Based Botnet Detection Toward Imbalanced Multiclass Learning (vol 26, pg 387, 2021)
    Chen, Yijing
    Pang, Bo
    Shao, Guolin
    Wen, Guozhu
    Chen, Xingshu
    TSINGHUA SCIENCE AND TECHNOLOGY, 2021, 26 (05) : 790 - 790
  • [22] Detection of Malicious Executable Files Based on Clustering of Activities
    Ognev, R. A.
    Zhukovskii, E., V
    Zegzhda, D. P.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2021, 55 (08) : 1092 - 1098
  • [23] Detection of Malicious Executable Files Based on Clustering of Activities
    R. A. Ognev
    E. V. Zhukovskii
    D. P. Zegzhda
    Automatic Control and Computer Sciences, 2021, 55 : 1092 - 1098
  • [24] BotCapturer: Detecting botnets based on two-layered analysis with graph anomaly detection and network traffic clustering
    Wang W.
    Wang Y.
    Tan X.
    Liu Y.
    Yang S.
    Wang, Wei (wangwei1@bjtu.edu.cn), 2018, Totem Publishers Ltd (14) : 1050 - 1059
  • [25] Group Abnormal Behavior Detection Based on Fuzzy Clustering
    Zhang, Huanhuan
    Zhang, Xi
    Xie, Jiarun
    Wang, Yashen
    PROCEEDINGS OF 2020 3RD INTERNATIONAL CONFERENCE ON UNMANNED SYSTEMS (ICUS), 2020, : 245 - 250
  • [26] Topic Detection based on Group Average Hierarchical Clustering
    Gao, Ni
    Gao, Ling
    He, Yiyue
    Wang, Hai
    Sun, Qian
    2013 INTERNATIONAL CONFERENCE ON ADVANCED CLOUD AND BIG DATA (CBD), 2013, : 88 - 92
  • [27] Towards Group-Activities Based Community Detection
    Kumar, Sumeet
    Carley, Kathleen M.
    PROCEEDINGS OF THE 2018 ACM INTERNATIONAL JOINT CONFERENCE ON PERVASIVE AND UBIQUITOUS COMPUTING AND PROCEEDINGS OF THE 2018 ACM INTERNATIONAL SYMPOSIUM ON WEARABLE COMPUTERS (UBICOMP/ISWC'18 ADJUNCT), 2018, : 1178 - 1183
  • [28] Abnormal crowd behavior detection based on motion clustering of mesoscopic group
    Zhang, Xuguang
    Wang, Mengwei
    Zuo, Jiaqian
    Li, Xiaoli
    Yi Qi Yi Biao Xue Bao/Chinese Journal of Scientific Instrument, 2015, 36 (05): : 1106 - 1114
  • [29] BotCatch: Botnet Detection Based on Coordinated Group Activities of Compromised Hosts
    Yahyazadeh, Mosa
    Abadi, Mahdi
    2014 7th International Symposium on Telecommunications (IST), 2014, : 941 - 945
  • [30] Enhancing Pedestrian Group Detection and Tracking Through Zone-Based Clustering
    Chen, Mingzuoyang
    Banitaan, Shadi
    Maleki, Mina
    IEEE ACCESS, 2023, 11 : 132162 - 132179