Fast Flux Watch: A mechanism for online detection of fast flux networks

被引:15
|
作者
Al-Duwairi, Basheer N. [1 ]
Al-Hammouri, Ahmad T. [1 ]
机构
[1] Jordan Univ Sci & Technol, Dept Network Engn & Secur, CyberSecur Res Lab, Irbid 22110, Jordan
关键词
Network security; Botnets; Fast flux networks; Bloom filter; Correlated TCP SYN;
D O I
10.1016/j.jare.2014.01.002
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Fast flux networks represent a special type of botnets that are used to provide highly available web services to a backend server, which usually hosts malicious content. Detection of fast flux networks continues to be a challenging issue because of the similar behavior between these networks and other legitimate infrastructures, such as CDNs and server farms. This paper proposes Fast Flux Watch (FF-Watch), a mechanism for online detection of fast flux agents. FF-Watch is envisioned to exist as a software agent at leaf routers that connect stub networks to the Internet. The core mechanism of FF-Watch is based on the inherent feature of fast flux networks: flux agents within stub networks take the role of relaying client requests to point-of-sale websites of spam campaigns. The main idea of FF-Watch is to correlate incoming TCP connection requests to flux agents within a stub network with outgoing TCP connection requests from the same agents to the point-of-sale website. Theoretical and traffic trace driven analysis shows that the proposed mechanism can be utilized to efficiently detect fast flux agents within a stub network. (C) 2014 Production and hosting by Elsevier B.V. on behalf of Cairo University.
引用
收藏
页码:473 / 479
页数:7
相关论文
共 50 条
  • [1] A Survey of Fast Flux Botnet Detection With Fast Flux Cloud Computing
    Al-Nawasrah, Ahmad
    Almomani, Ammar Ali
    Atawneh, Samer
    Alauthman, Mohammad
    INTERNATIONAL JOURNAL OF CLOUD APPLICATIONS AND COMPUTING, 2020, 10 (03) : 17 - 53
  • [2] Fast-flux hunter: a system for filtering online fast-flux botnet
    Almomani, Ammar
    NEURAL COMPUTING & APPLICATIONS, 2018, 29 (07): : 483 - 493
  • [3] Fast-flux hunter: a system for filtering online fast-flux botnet
    Ammar Almomani
    Neural Computing and Applications, 2018, 29 : 483 - 493
  • [4] Real-Time Detection of Fast Flux Service Networks
    Caglayan, Alper
    Toothaker, Mike
    Drapeau, Dan
    Burke, Dustin
    Eaton, Gerry
    CATCH 2009: CYBERSECURITY APPLICATIONS AND TECHNOLOGY CONFERENCE FOR HOMELAND SECURITY, PROCEEDINGS, 2009, : 285 - 292
  • [5] Behavioral Patterns of Fast Flux Service Networks
    Caglayan, Alper
    Toothaker, Mike
    Drapaeau, Dan
    Burke, Dustin
    Eaton, Gerry
    43RD HAWAII INTERNATIONAL CONFERENCE ON SYSTEMS SCIENCES VOLS 1-5 (HICSS 2010), 2010, : 900 - 908
  • [6] ONLINE NOISE MONITORING AT THE FAST FLUX TEST FACILITY
    MULLENS, JA
    THIE, JA
    CAMPBELL, LR
    PROGRESS IN NUCLEAR ENERGY, 1985, 15 (1-3) : 483 - 489
  • [7] Detection of Fast-Flux Networks Using Various DNS Feature Sets
    Celik, Z. Berkay
    Oktug, Serna
    2013 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2013,
  • [8] Fast Flux Module Detection Using Matroid Theory
    Mueller, Arne C.
    Bruggeman, Frank J.
    Olivier, Brett G.
    Stougie, Leen
    RESEARCH IN COMPUTATIONAL MOLECULAR BIOLOGY, RECOMB2014, 2014, 8394 : 192 - 206
  • [9] Formulistic Detection of Malicious Fast-Flux Domains
    Chen, Chia-Mei
    Cheng, Sheng-Tzong
    Chou, Ju-Hsien
    Ou, Ya-Hui
    2012 FIFTH INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS AND PROGRAMMING (PAAP), 2012, : 72 - 79
  • [10] Fast-Flux Bot Detection in Real Time
    Hsu, Ching-Hsiang
    Huang, Chun-Ying
    Chen, Kuan-Ta
    RECENT ADVANCES IN INTRUSION DETECTION, 2010, 6307 : 464 - +