FluXOR: Detecting and monitoring fast-flux service networks

被引:0
|
作者
Passerini, Emanuele [1 ]
Paleari, Roberto [1 ]
Martignoni, Lorenzo [1 ]
Bruschi, Danilo [1 ]
机构
[1] Univ Milan, I-20122 Milan, Italy
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnets are large groups of compromised machines (bots) used by miscreants for the most illegal activities (e.g., sending spam emails, denial-of-service attacks, phishing and other web scams). To protect the identity and to maximise the availability of the core components of their business, miscreants have recently started to use fast-flux service networks, large groups of bots acting as front-end proxies to these components. Motivated by the conviction that prompt detection and. monitoring of these networks is an essential step to contrast the problem posed by botnets, we have developed FluXOR, a system to detect and monitor fast-flux service networks. FluXOR monitoring and detection strategies entirely rely on the analysis of a set of features observable from the point of view of a victim of the scams perpetrated thorough botnets. We have been using FluXOR for about a month and so far we have detected 387 fast-flux service networks, totally composed by 31998 distinct compromised machines, which we believe to be associated with 16 botnets.
引用
收藏
页码:186 / 206
页数:21
相关论文
共 50 条
  • [11] Fast-Flux Bot Detection in Real Time
    Hsu, Ching-Hsiang
    Huang, Chun-Ying
    Chen, Kuan-Ta
    RECENT ADVANCES IN INTRUSION DETECTION, 2010, 6307 : 464 - +
  • [12] As the Net Churns: Fast-Flux Botnet Observations
    Nazario, Jose
    Holz, Thorsten
    MALWARE 2008: PROCEEDINGS OF THE 2008 3RD INTERNATIONAL CONFERENCE ON MALICIOUS AND UNWANTED SOFTWARE, 2008, : 29 - 36
  • [13] Formulistic Detection of Malicious Fast-Flux Domains
    Chen, Chia-Mei
    Cheng, Sheng-Tzong
    Chou, Ju-Hsien
    Ou, Ya-Hui
    2012 FIFTH INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS AND PROGRAMMING (PAAP), 2012, : 72 - 79
  • [14] TR-SRE - FAST-FLUX IRRADIATION FACILITY
    CAMPISE, AV
    TRANSACTIONS OF THE AMERICAN NUCLEAR SOCIETY, 1964, 7 (02): : 306 - &
  • [15] Fast-flux Botnet Detection from Network Traffic
    Paul, Tuhin
    Tyagi, Rohit
    Manoj, B. S.
    Thanudas, B.
    2014 ANNUAL IEEE INDIA CONFERENCE (INDICON), 2014,
  • [16] Behavioral Patterns of Fast Flux Service Networks
    Caglayan, Alper
    Toothaker, Mike
    Drapaeau, Dan
    Burke, Dustin
    Eaton, Gerry
    43RD HAWAII INTERNATIONAL CONFERENCE ON SYSTEMS SCIENCES VOLS 1-5 (HICSS 2010), 2010, : 900 - 908
  • [17] Detect Fast-Flux Domains Through Response Time Differences
    Hsu, Fu-Hau
    Wang, Chuan-Sheng
    Hsu, Chi-Hsien
    Tso, Chang-Kuo
    Chen, Li-Han
    Lin, Song-Hui
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2014, 32 (10) : 1947 - 1956
  • [18] Fast-flux Attack Network Identification Based on Agent Lifespan
    Yu, Sheng
    Zhou, Shijie
    Wang, Sha
    2010 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND INFORMATION SECURITY (WCNIS), VOL 1, 2010, : 658 - 662
  • [19] 基于Fast-Flux的DNS异常行为分析
    李骜骋
    王峥
    计算机工程, 2018, 44 (12) : 184 - 189+195
  • [20] Detection of fast-flux botnets through DNS traffic analysis
    Soltanaghaei, E.
    Kharrazi, M.
    SCIENTIA IRANICA, 2015, 22 (06) : 2389 - 2400