Genetic-based Real-time Fast-Flux Service Networks Detection

被引:19
|
作者
Lin, Hui-Tang [1 ,2 ]
Lin, Ying-You [2 ]
Chiang, Jui-Wei [2 ]
机构
[1] Natl Cheng Kung Univ, Dept Elect Engn, Tainan 70101, Taiwan
[2] Natl Cheng Kung Univ, Inst Comp & Commun Engn, Tainan 70101, Taiwan
关键词
Network security; Fast-flux service networks; Botnets; ALGORITHMS;
D O I
10.1016/j.comnet.2012.07.017
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A new DNS technique called Fast-Flux Service Network (FFSN) has been employed by bot herders to hide malicious activities and extend the lifetime of malicious root servers. Although various methods have been proposed for detecting FFSNs, these mechanisms have low detection accuracy and protracted detection time. This study presents a novel detection scheme, designated as the Genetic-based ReAl-time DEtection (GRADE) system, to identify FFSNs in real time. GRADE differentiates between FFSNs and benign services by employing two new characteristics: the entropy of domains of preceding nodes for all A records and the standard deviation of round trip time to all A records. By applying genetic algorithms, GRADE is able to find the best strategy to detect current FFSN trends. Empirical results show GRADE has very high detection accuracy (similar to 98%) and gives results within a few seconds. It provides considerable improvement over existing reference schemes such Flux-Score [9], FFBD [13] and SSFD [14]. (c) 2012 Elsevier B.V. All rights reserved.
引用
收藏
页码:501 / 513
页数:13
相关论文
共 50 条
  • [31] Real-time service provisioning for mobile and wireless networks
    Farkas, K
    Wellnitz, O
    Dick, M
    Gu, X
    Busse, M
    Effelsberg, W
    Rebahi, Y
    Sisalem, D
    Grigoras, D
    Stefanidis, K
    Serpanos, DN
    COMPUTER COMMUNICATIONS, 2006, 29 (05) : 540 - 550
  • [32] Providing real-time service in CDMA wireless networks
    Ma, Maode
    Zhu, Qichao
    WIRELESS PERSONAL COMMUNICATIONS, 2007, 41 (04) : 551 - 562
  • [33] RTSS: A CORBA-based real-time stream service for ATM networks
    Sapkota, BS
    Pung, HK
    Ngoh, LH
    Wong, L
    ICICS - PROCEEDINGS OF 1997 INTERNATIONAL CONFERENCE ON INFORMATION, COMMUNICATIONS AND SIGNAL PROCESSING, VOLS 1-3: THEME: TRENDS IN INFORMATION SYSTEMS ENGINEERING AND WIRELESS MULTIMEDIA COMMUNICATIONS, 1997, : 611 - 616
  • [34] Embedded Real-Time Detection of Vehicles and Pedestrians Based on Minimal Networks
    Tian, Zhenghao
    MOBILE INFORMATION SYSTEMS, 2022, 2022
  • [35] Real-time raindrop detection based on cellular neural networks for ADAS
    Fadi Al Machot
    Mouhannad Ali
    Ahmad Haj Mosa
    Christopher Schwarzlmüller
    Markus Gutmann
    Kyandoghere Kyamakya
    Journal of Real-Time Image Processing, 2019, 16 : 931 - 943
  • [36] Real-time raindrop detection based on cellular neural networks for ADAS
    Al Machot, Fadi
    Ali, Mouhannad
    Mosa, Ahmad Haj
    Schwarzlmueller, Christopher
    Gutmann, Markus
    Kyamakya, Kyandoghere
    JOURNAL OF REAL-TIME IMAGE PROCESSING, 2019, 16 (04) : 931 - 943
  • [37] Geo-Spatial Autocorrelation as a Metric for the Detection of Fast-Flux Botnet Domains
    Stalmans, Etienne
    Hunter, Samuel Oswald
    Irwin, Barry
    2012 INFORMATION SECURITY FOR SOUTH AFRICA (ISSA), 2012,
  • [38] Hybrid Detection and Tracking of Fast-Flux Botnet on Domain Name System Traffic
    Zou Futai
    Zhang Siyu
    Rao Weixiong
    CHINA COMMUNICATIONS, 2013, 10 (11) : 81 - 94
  • [39] Botnet Attack Detection Using A Hybrid Supervised Fast-Flux Killer System
    Al-Nawasrah, Ahmad
    Almomani, Ammar
    Al-Issa, Huthaifa A.
    Alissa, Khalid
    Alrosan, Ayat
    Alaboudi, Abdulellah A.
    Gupta, Brij B.
    JOURNAL OF WEB ENGINEERING, 2022, 21 (02): : 179 - 201
  • [40] Fast face detection method based on real-time prediction and learning classification
    Liu, C. (liuchang_0117@hotmail.com), 1600, Science Press (33):