FluXOR: Detecting and monitoring fast-flux service networks

被引:0
|
作者
Passerini, Emanuele [1 ]
Paleari, Roberto [1 ]
Martignoni, Lorenzo [1 ]
Bruschi, Danilo [1 ]
机构
[1] Univ Milan, I-20122 Milan, Italy
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Botnets are large groups of compromised machines (bots) used by miscreants for the most illegal activities (e.g., sending spam emails, denial-of-service attacks, phishing and other web scams). To protect the identity and to maximise the availability of the core components of their business, miscreants have recently started to use fast-flux service networks, large groups of bots acting as front-end proxies to these components. Motivated by the conviction that prompt detection and. monitoring of these networks is an essential step to contrast the problem posed by botnets, we have developed FluXOR, a system to detect and monitor fast-flux service networks. FluXOR monitoring and detection strategies entirely rely on the analysis of a set of features observable from the point of view of a victim of the scams perpetrated thorough botnets. We have been using FluXOR for about a month and so far we have detected 387 fast-flux service networks, totally composed by 31998 distinct compromised machines, which we believe to be associated with 16 botnets.
引用
收藏
页码:186 / 206
页数:21
相关论文
共 50 条
  • [41] Fast-Flux Botnet Detection Based on Traffic Response and Search Engines Credit Worthiness
    Cafuta, Davor
    Sruk, Vlado
    Dodig, Ivica
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2018, 25 (02): : 390 - 400
  • [42] 基于流量时空特征的fast-flux僵尸网络检测方法
    牛伟纳
    蒋天宇
    张小松
    谢娇
    张俊哲
    赵振扉
    电子与信息学报, 2020, 42 (08) : 1872 - 1880
  • [43] Characterization of the Fast-Neutron Irradiator and the Fast-Flux Tube Irradiation Fixtures at the Pennsylvania State Breazeale Reactor
    Kuatbek, Maksat
    Pierson, Bruce D.
    Lyons, Stephanie M.
    Flaska, Marek
    Johnsen, Amanda M.
    NUCLEAR ENGINEERING AND DESIGN, 2023, 413
  • [44] GEOMETRY PROBLEMS ENCOUNTERED WITH FAST-FLUX TEST FACILITY (FFTF) SPLIT CONICAL CORE
    WAYMIRE, GR
    PETERSON, RE
    FINCH, LM
    TRANSACTIONS OF THE AMERICAN NUCLEAR SOCIETY, 1967, 10 (02): : 646 - &
  • [45] 基于SVM的Fast-flux僵尸网络检测技术研究
    康乐
    李东
    余翔湛
    智能计算机与应用, 2011, 1 (03) : 24 - 27
  • [46] 基于多模态特征融合的Fast-Flux恶意域名检测方法
    郎波
    谢冲
    陈少杰
    刘宏宇
    信息网络安全, 2022, 22 (04) : 20 - 29
  • [47] Detecting Malicious Flux Service Networks through Passive Analysis of Recursive DNS Traces
    Perdisci, Roberto
    Corona, Igino
    Dagon, David
    Lee, Wenke
    25TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, 2009, : 311 - +
  • [48] 基于代理控制力的Fast-Flux僵尸网络检测方法
    刘资茂
    李芝棠
    李战春
    李冬
    方平
    广西大学学报(自然科学版), 2011, 36(S1) (自然科学版) : 105 - 109
  • [49] Real-time Malicious Fast-flux Detection Using DNS and Bot Related Features
    Martinez-Bea, Sergi
    Castillo-Perez, Sergio
    Garcia-Alfaro, Joaquin
    2013 ELEVENTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2013, : 369 - 372
  • [50] 基于网络流量的Fast-Flux僵尸网络域名检测方法
    谷勇浩
    郭振洋
    信息安全研究, 2020, 6 (05) : 388 - 395