Kindred Domains: Detecting and Clustering Botnet Domains Using DNS Traffic

被引:41
|
作者
Thomas, Matthew [1 ]
Mohaisen, Aziz [1 ]
机构
[1] Verisign Labs, Reston, VA 20190 USA
关键词
Malware; Clustering; Automatic Analysis; DNS;
D O I
10.1145/2567948.2579359
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we focus on detecting and clustering distinct groupings of domain names that are queried by numerous sets of infected machines. We propose to analyze domain name system (DNS) traffic, such as Non-Existent Domain (NXDomain) queries, at several premier Top Level Domain (TLD) authoritative name servers to identify strongly connected cliques of malware related domains. We illustrate typical malware DNS lookup patterns when observed on a global scale and utilize this insight to engineer a system capable of detecting and accurately clustering malware domains to a particular variant or malware family without the need for obtaining a malware sample. Finally, the experimental results of our system will provide a unique perspective on the current state of globally distributed malware, particularly the ones that use DNS.
引用
收藏
页码:707 / 712
页数:6
相关论文
共 50 条
  • [31] Detecting IoT Botnet Formation using Data Stream Clustering Algorithms
    Arimatea, Gabriel de Carvalho
    Lima Ribeiro, Admilson de Ribamar
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES (WEBIST), 2020, : 395 - 402
  • [32] Detecting the presence of membrane domains using DSC
    Epand, Richard M.
    BIOPHYSICAL CHEMISTRY, 2007, 126 (1-3) : 197 - 200
  • [33] Detecting Phishing Domains Using Machine Learning
    Alnemari, Shouq
    Alshammari, Majid
    APPLIED SCIENCES-BASEL, 2023, 13 (08):
  • [34] Detecting botnets by analyzing DNS traffic
    Tu, Hao
    Li, Zhi-Tang
    Liu, Bin
    INTELLIGENCE AND SECURITY INFORMATICS, 2007, 4430 : 323 - +
  • [35] Detecting Encrypted Botnet Traffic Using Spatial-Temporal Correlation
    Wei, Chen
    Le, Yu
    Geng, Yang
    CHINA COMMUNICATIONS, 2012, 9 (10) : 49 - 59
  • [36] Identifying structural domains of proteins using clustering
    Feldman, Howard J.
    BMC BIOINFORMATICS, 2012, 13
  • [37] Identifying structural domains of proteins using clustering
    Howard J Feldman
    BMC Bioinformatics, 13
  • [38] A Botnet Detecting Infrastructure Using a Beneficial Botnet
    Yamanoue, Takashi
    PROCEEDINGS OF THE 2018 ACM SIGUCCS ANNUAL CONFERENCE (SIGUCCS '18), 2018, : 35 - 42
  • [39] Design of detecting botnet communication by monitoring direct outbound DNS queries
    Jin, Yong
    Ichise, Hikaru
    Iida, Katsuyoshi
    2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing (CSCloud), 2015, : 37 - 41
  • [40] Conformal Clustering and Its Application to Botnet Traffic
    Cherubin, Giovanni
    Nouretdinov, Ilia
    Gammerman, Alexander
    Jordaney, Roberto
    Wang, Zhi
    Papini, Davide
    Cavallaro, Lorenzo
    STATISTICAL LEARNING AND DATA SCIENCES, 2015, 9047 : 313 - 322