Early Detection of Malicious Flux Networks via Large-Scale Passive DNS Traffic Analysis

被引:72
|
作者
Perdisci, Roberto [1 ]
Corona, Igino [2 ]
Giacinto, Giorgio [2 ]
机构
[1] Univ Georgia, Dept Comp Sci, Boyd Grad Studies Res Ctr 415, Athens, GA 30602 USA
[2] Univ Cagliari, Dept Elect & Elect Engn, I-09123 Cagliari, Italy
基金
美国国家科学基金会;
关键词
Flux networks; DNS; passive traffic analysis; clustering; classification; Internet security;
D O I
10.1109/TDSC.2012.35
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present FluxBuster, a novel passive DNS traffic analysis system for detecting and tracking malicious flux networks. FluxBuster applies large-scale monitoring of DNS traffic traces generated by recursive DNS (RDNS) servers located in hundreds of different networks scattered across several different geographical locations. Unlike most previous work, our detection approach is not limited to the analysis of suspicious domain names extracted from spam emails or precompiled domain blacklists. Instead, FluxBuster is able to detect malicious flux service networks in-the-wild, i.e., as they are "accessed" by users who fall victim of malicious content, independently of how this malicious content was advertised. We performed a long-term evaluation of our system spanning a period of about five months. The experimental results show that FluxBuster is able to accurately detect malicious flux networks with a low false positive rate. Furthermore, we show that in many cases FluxBuster is able to detect malicious flux domains several days or even weeks before they appear in public domain blacklists.
引用
收藏
页码:714 / 726
页数:13
相关论文
共 50 条
  • [41] Community Detection in Large-scale Bipartite Networks
    Liu, Xin
    Murata, Tsuyoshi
    [J]. 2009 IEEE/WIC/ACM INTERNATIONAL JOINT CONFERENCES ON WEB INTELLIGENCE (WI) AND INTELLIGENT AGENT TECHNOLOGIES (IAT), VOL 1, 2009, : 50 - 57
  • [42] On The Detection of DDoS Attackers for Large-Scale Networks
    Nashat, Dalia
    Jiang, Xiaohong
    Horiguchi, Susumu
    [J]. ICEBE 2009: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2009, : 206 - 212
  • [43] REMaDD: Resource-Efficient Malicious Domains Detector in Large-Scale Networks
    Kdosha, Ofir Erets
    Rosenthal, Gilad
    Cohen, Kobi
    Freund, Alon
    Bartik, Avishay
    Ron, Aviv
    [J]. IEEE ACCESS, 2020, 8 : 66327 - 66337
  • [44] Security Risk Analysis of Active Distribution Networks with Large-Scale Controllable Loads under Malicious Attacks
    Liang, Jiaqi
    Wu, Yibei
    Li, Jun'e
    Chen, Xiong
    Tong, Heqin
    Ni, Ming
    [J]. COMPLEXITY, 2021, 2021
  • [45] The simulation and analysis of the large-scale intrusion detection model in shuffle networks
    Likewei
    [J]. MECHATRONICS ENGINEERING, COMPUTING AND INFORMATION TECHNOLOGY, 2014, 556-562 : 2878 - 2881
  • [46] Realtime Robust Malicious Traffic Detection via Frequency Domain Analysis
    Fu, Chuanpu
    Li, Qi
    Shen, Meng
    Xu, Ke
    [J]. CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 3431 - 3446
  • [47] No Honor Among Thieves: A Large-Scale Analysis of Malicious Web Shells
    Starov, Oleksii
    Dahse, Johannes
    Ahmad, Syed Sharique
    Holz, Thorsten
    Nikiforakis, Nick
    [J]. PROCEEDINGS OF THE 25TH INTERNATIONAL CONFERENCE ON WORLD WIDE WEB (WWW'16), 2016, : 1021 - 1032
  • [48] Demand estimation for perimeter control in large-scale traffic networks
    Kumarage, Sakitha
    Yildirimoglu, Mehmet
    Zheng, Zuduo
    [J]. 2023 8TH INTERNATIONAL CONFERENCE ON MODELS AND TECHNOLOGIES FOR INTELLIGENT TRANSPORTATION SYSTEMS, MT-ITS, 2023,
  • [49] Cooperative Bayesian Estimation of Vehicular Traffic in Large-Scale Networks
    Pascale, Alessandra
    Nicoli, Monica
    Spagnolini, Umberto
    [J]. IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2014, 15 (05) : 2074 - 2088
  • [50] A delay propagation algorithm for large-scale railway traffic networks
    Goverde, Rob M. P.
    [J]. TRANSPORTATION RESEARCH PART C-EMERGING TECHNOLOGIES, 2010, 18 (03) : 269 - 287