Bot detection by monitoring and grouping domain name server record response queries in DNS traffic

被引:3
|
作者
Vyas, Abhilasha [1 ]
Batra, Usha [1 ]
机构
[1] GD Goenka Univ, Dept Comp Sci & Engn, Gurgaon 122103, Haryana, India
来源
关键词
DNS; DNSRR; Botnet detection; Record Response; DNS query; SYSTEMS;
D O I
10.1080/02522667.2019.1639945
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
A Botnet is network of bots or infected systems, each running on a compromised host machine, controlled by command and control server. Botnet can be used for email spamming to launching DDoS attacks. Botnet attacks classified as topology based, protocol based, and architecture based. Designing a detection system for bots is becoming challenging as botnet attacks are upgrading the attacking methodology by hiding and changing identities (command and control server) periodically. This paper is proposing, bot detection methodology by monitoring domain name server record response (DNSRR) query traffic, which form a group activity in DNS traffic simultaneously sent by bot machines. The analysis is based on type of botnet attack, detection target, feature source, feature extraction, feature correlation, machine learning techniques. Few researchers proposed bot detection techniques based on DNS queries initiated by bots, but these can be easily avoided by changing bot program, architecture, protocol and encrypted network traffic. The proposed approach is versatile and robust than the existing detection approaches so that the presence of variety of bots can be detected by monitoring the group activities of DNSRR queries in DNS traffic. From the experiment and results, it is shown that proposed methodology able to detect bot efficiently while they are connected to controlling server or migrating to new server. The results are encouraging because of low false positive detection rate.
引用
收藏
页码:1143 / 1153
页数:11
相关论文
共 29 条
  • [1] Multi-layer domain name detection and measurement based on DNS traffic
    Zhang Y.-X.
    Gong J.
    [J]. Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science), 2020, 54 (12): : 2423 - 2429and2436
  • [2] Estimation of domain name system (DNS) server load distribution
    Zheng, Wang
    [J]. SCIENTIFIC RESEARCH AND ESSAYS, 2014, 9 (13): : 619 - 624
  • [3] Detecting Anomalies at a TLD Name Server Based on DNS Traffic Predictions
    Madariaga, Diego
    Madariaga, Javier
    Panza, Martin
    Bustos-Jimenez, Javier
    Bustos, Benjamin
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01): : 1016 - 1030
  • [4] DNS: A statistical analysis of name server traffic at local network-to-Internet connections
    Brandhorst, C
    Pras, A
    [J]. EUNICE 2005: NETWORKS AND APPLICATIONS TOWARDS A UBIQUITOUSLY CONNECTED WORLD, 2006, 196 : 255 - +
  • [5] Malware Detection using DNS Records and Domain Name Features
    Al Messabi, Khulood
    Aldwairi, Monther
    Al Yousif, Ayesha
    Thoban, Anoud
    Belqasmi, Fatna
    [J]. ICFNDS'18: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND DISTRIBUTED SYSTEMS, 2018,
  • [6] An Adaptive Malicious Domain Detection Mechanism with DNS Traffic
    ShuoXu
    Li, ShuQin
    Meng, Kun
    Wu, LiJun
    Ding, Meng
    [J]. PROCEEDINGS OF 2017 VI INTERNATIONAL CONFERENCE ON NETWORK, COMMUNICATION AND COMPUTING (ICNCC 2017), 2017, : 86 - 91
  • [7] Fast-flucos: malicious domain name detection method for Fast-flux based on DNS traffic
    Han C.
    Zhang Y.
    Zhang Y.
    [J]. Tongxin Xuebao/Journal on Communications, 2020, 41 (05): : 37 - 47
  • [8] Detection of Hijacked Authoritative DNS Servers by Name Resolution Traffic Classification
    Jin, Yong
    Tomoishi, Masahiko
    Matsuura, Satoshi
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2019, : 6084 - 6085
  • [9] Detection of Hijacked Authoritative DNS Servers by Name Resolution Traffic Classification
    Jin, Yong
    Tomoishi, Masahiko
    Matsuura, Satoshi
    [J]. Proceedings - 2019 IEEE International Conference on Big Data, Big Data 2019, 2019, : 6084 - 6085
  • [10] Botnet detection by monitoring group activities in DNS traffic
    Choi, Hyunsang
    Lee, Hanwoo
    Lee, Heejo
    Kim, Hyogon
    [J]. 2007 CIT: 7TH IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY, PROCEEDINGS, 2007, : 715 - 720