BotCVD: Visual analysis of DNS traffic for botnet detection

被引:0
|
作者
机构
[1] Jiang, Hongling
[2] Liu, Yiwei
[3] Shao, Xiuli
来源
Jiang, H. (hellojhl@163.com) | 1600年 / Advanced Institute of Convergence Information Technology卷 / 04期
关键词
Cluster computing - Internet protocols;
D O I
10.4156/AISS.vol4.issue8.32
中图分类号
学科分类号
摘要
Botnets become one of the serious threats to the Internet. In this paper, we design a light-weighted approach-BotCVD (Bot Cluster Visual Detector) to detect botnet by visually analyzing DNS traffic. To avoid the confusion of the normal DNS traffic, BotCVD analyzes the features of server-host pairs instead of single hosts. Since bots in the same botnet behave similarly in DNS queries, BotCVD visually cluster server-host pairs by computing the dissimilarity matrix of server-host pairs. Through an ordered dissimilarity image, BotCVD could clearly show botnet clusters and detect the infected hosts and malicious servers. Experimental results on real-world network traces merged with synthetic botnet traces indicate that BotCVD can (i) visualize botnet clusters and (ii) detect botnets with a high detection rate and a low false positive rate.
引用
收藏
相关论文
共 50 条
  • [1] A Review of Botnet Detection Approaches Based on DNS Traffic Analysis
    Al-Mashhadi, Saif
    Anbar, Mohammed
    Karuppayah, Shankar
    Al-Ani, Ahmed K.
    INTELLIGENT AND INTERACTIVE COMPUTING, 2019, 67 : 305 - 321
  • [2] A Technique for the Botnet Detection Based on DNS-Traffic Analysis
    Pomorova, Oksana
    Savenko, Oleg
    Lysenko, Sergii
    Kryshchuk, Andrii
    Bobrovnikova, Kira
    COMPUTER NETWORKS, CN 2015, 2015, 522 : 127 - 138
  • [3] Holistic Model for HTTP Botnet Detection Based on DNS Traffic Analysis
    Alenazi, Abdelraman
    Traore, Issa
    Ganame, Karim
    Woungang, Isaac
    INTELLIGENT, SECURE, AND DEPENDABLE SYSTEMS IN DISTRIBUTED AND CLOUD ENVIRONMENTS (ISDDC 2017), 2017, 10618 : 1 - 18
  • [4] Botnet detection by monitoring group activities in DNS traffic
    Choi, Hyunsang
    Lee, Hanwoo
    Lee, Heejo
    Kim, Hyogon
    2007 CIT: 7TH IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY, PROCEEDINGS, 2007, : 715 - 720
  • [5] BotMAD: Botnet Malicious Activity Detector Based on DNS Traffic Analysis
    Sharma, Pooja
    Kumar, Sanjeev
    Sharma, Neeraj
    PROCEEDINGS ON 2016 2ND INTERNATIONAL CONFERENCE ON NEXT GENERATION COMPUTING TECHNOLOGIES (NGCT), 2016, : 824 - 830
  • [6] PsyBoG: A scalable botnet detection method for large-scale DNS traffic
    Kwon, Jonghoon
    Lee, Jehyun
    Lee, Heejo
    Perrig, Adrian
    COMPUTER NETWORKS, 2016, 97 : 48 - 73
  • [7] IRC traffic analysis for botnet detection
    Mazzariello, Claudio
    FOURTH INTERNATIONAL SYMPOSIUM ON INFORMATION ASSURANCE AND SECURITY, PROCEEDINGS, 2008, : 318 - 323
  • [8] A survey of botnet detection based on DNS
    Kamal Alieyan
    Ammar ALmomani
    Ahmad Manasrah
    Mohammed M. Kadhum
    Neural Computing and Applications, 2017, 28 : 1541 - 1558
  • [9] A survey of botnet detection based on DNS
    Alieyan, Kamal
    ALmomani, Ammar
    Manasrah, Ahmad
    Kadhum, Mohammed M.
    NEURAL COMPUTING & APPLICATIONS, 2017, 28 (07): : 1541 - 1558
  • [10] Botnet Detection Technology Based on DNS
    Li, Xingguo
    Wang, Junfeng
    Zhang, Xiaosong
    FUTURE INTERNET, 2017, 9 (04)