BotCVD: Visual analysis of DNS traffic for botnet detection

被引:0
|
作者
机构
[1] Jiang, Hongling
[2] Liu, Yiwei
[3] Shao, Xiuli
来源
Jiang, H. (hellojhl@163.com) | 1600年 / Advanced Institute of Convergence Information Technology卷 / 04期
关键词
Cluster computing - Internet protocols;
D O I
10.4156/AISS.vol4.issue8.32
中图分类号
学科分类号
摘要
Botnets become one of the serious threats to the Internet. In this paper, we design a light-weighted approach-BotCVD (Bot Cluster Visual Detector) to detect botnet by visually analyzing DNS traffic. To avoid the confusion of the normal DNS traffic, BotCVD analyzes the features of server-host pairs instead of single hosts. Since bots in the same botnet behave similarly in DNS queries, BotCVD visually cluster server-host pairs by computing the dissimilarity matrix of server-host pairs. Through an ordered dissimilarity image, BotCVD could clearly show botnet clusters and detect the infected hosts and malicious servers. Experimental results on real-world network traces merged with synthetic botnet traces indicate that BotCVD can (i) visualize botnet clusters and (ii) detect botnets with a high detection rate and a low false positive rate.
引用
收藏
相关论文
共 50 条
  • [21] BOTNET DETECTION BASED ON DNS RECORDS AND ACTIVE PROBING
    Prieto, Iria
    Magana, Eduardo
    Morato, Daniel
    Izal, Mikel
    SECRYPT 2011: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2011, : 307 - 316
  • [22] DNS rule-based schema to botnet detection
    Alieyan, Kamal
    Almomani, Ammar
    Anbar, Mohammed
    Alauthman, Mohammad
    Abdullah, Rosni
    Gupta, B. B.
    ENTERPRISE INFORMATION SYSTEMS, 2021, 15 (04) : 545 - 564
  • [23] Kindred Domains: Detecting and Clustering Botnet Domains Using DNS Traffic
    Thomas, Matthew
    Mohaisen, Aziz
    WWW'14 COMPANION: PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON WORLD WIDE WEB, 2014, : 707 - 712
  • [24] Peer to Peer Botnet Detection Based on Network Traffic Analysis
    Almutairi, Suzan
    Mahfoudh, Saoucene
    Alowibdi, Jalal S.
    2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [25] Botnet detection based on traffic behavior analysis and flow intervals
    Zhao, David
    Traore, Issa
    Sayed, Bassam
    Lu, Wei
    Saad, Sherif
    Ghorbani, Ali
    Garant, Dan
    COMPUTERS & SECURITY, 2013, 39 : 2 - 16
  • [26] Sliding Time Analysis in Traffic Segmentation for Botnet Activity Detection
    Hostiadi, Dandy Pramana
    Ahmad, Tohari
    5TH INTERNATIONAL CONFERENCE ON COMPUTING AND INFORMATICS (ICCI 2022), 2022, : 286 - 291
  • [27] Smart Approach for Botnet Detection Based on Network Traffic Analysis
    Obeidat, Alaa
    Yaqbeh, Rola
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2022, 2022
  • [28] Analysis of via-resolver DNS TXT queries and detection possibility of botnet communications
    Ichise, Hikaru
    Jin, Yong
    Iida, Katsuyoshi
    IEICE COMMUNICATIONS EXPRESS, 2016, 5 (03): : 74 - 78
  • [29] Analysis of Via-Resolver DNS TXT Queries and Detection Possibility of Botnet Communications
    Ichise, Hikaru
    Jin, Yong
    Iida, Katsuyoshi
    2015 IEEE PACIFIC RIM CONFERENCE ON COMMUNICATIONS, COMPUTERS AND SIGNAL PROCESSING (PACRIM), 2015, : 216 - 221
  • [30] Botnet Detection Based on Traffic Monitoring
    Zeidanloo, Hossein Rouhani
    Manaf, Azizah Bt
    Vahdani, Payam
    Tabatabaei, Farzaneh
    Zamani, Mazdak
    2010 INTERNATIONAL CONFERENCE ON NETWORKING AND INFORMATION TECHNOLOGY (ICNIT 2010), 2010, : 97 - 101