Detection of Fast-Flux Networks Using Various DNS Feature Sets

被引:0
|
作者
Celik, Z. Berkay [1 ]
Oktug, Serna [1 ]
机构
[1] Istanbul Tech Univ, Dept Comp Engn, TR-34469 Istanbul, Turkey
关键词
network security; Fast-flux Service Networks (FFSNs); feature selection; classification;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this work, we study the detection of Fast-Flux Service Networks (FFSNs) using DNS (Domain Name System) response packets. We have observed that current approaches do not employ a large combination of DNS features to feed into the proposed detection systems. The lack of features may lead to high false positive or false negative rates triggered by benign activities including Content Distribution Networks (CDNs). In this paper, we study recently proposed detection frameworks to construct a high-dimensional feature vector containing timing, network, spatial, domain name, and DNS response information. In the detection system, we strive to use features that are delayfree, and lightweight in terms of storage and computational cost. Feature sub-spaces are evaluated using a C4.5 decision tree classifier by excluding redundant features using the information gain of each feature with respect to each class. Our experiments reveal the performance of each feature subset type in terms of the classification accuracy. Moreover, we present the best feature subset for the discrimination of FFSNs recorded with the datasets we used.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] 基于DNS流量的Fast-Flux僵尸网络混合检测与追踪(英文)
    邹福泰
    章思宇
    饶卫雄
    中国通信, 2013, 10 (11) : 81 - 94
  • [22] Geo-Spatial Autocorrelation as a Metric for the Detection of Fast-Flux Botnet Domains
    Stalmans, Etienne
    Hunter, Samuel Oswald
    Irwin, Barry
    2012 INFORMATION SECURITY FOR SOUTH AFRICA (ISSA), 2012,
  • [23] Hybrid Detection and Tracking of Fast-Flux Botnet on Domain Name System Traffic
    Zou Futai
    Zhang Siyu
    Rao Weixiong
    CHINA COMMUNICATIONS, 2013, 10 (11) : 81 - 94
  • [24] Robust object detection using fast feature selection from huge feature sets
    Le, Duy-Dinh
    Satoh, Shin'ichi
    2006 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP 2006, PROCEEDINGS, 2006, : 961 - +
  • [25] Real-time Fast-flux Identification via Localized Spatial Geolocation Detection
    Wang, Horng-Tzer
    Mao, Ching-Hao
    Wu, Kuo-Ping
    Lee, Hahn-Ming
    2012 IEEE 36TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), 2012, : 244 - 252
  • [26] Fast-Flux Botnet Detection Based on Traffic Response and Search Engines Credit Worthiness
    Cafuta, Davor
    Sruk, Vlado
    Dodig, Ivica
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2018, 25 (02): : 390 - 400
  • [27] MISHIMA: Multilateration of Internet Hosts Hidden Using Malicious Fast-Flux Agents
    Banks, Greg
    Fattori, Aristide
    Kemmerer, Richard
    Kruegel, Christopher
    Vigna, Giovanni
    DETECTION OF INTRUSIONS AND MALWARE, AND VULNERABILITY ASSESSMENT, 2011, 6739 : 184 - 193
  • [28] Fast Flux Watch: A mechanism for online detection of fast flux networks
    Al-Duwairi, Basheer N.
    Al-Hammouri, Ahmad T.
    JOURNAL OF ADVANCED RESEARCH, 2014, 5 (04) : 473 - 479
  • [29] Good Guys vs. Bot Guise: Mimicry Attacks Against Fast-Flux Detection Systems
    Knysz, Matthew
    Hu, Xin
    Shin, Kang G.
    2011 PROCEEDINGS IEEE INFOCOM, 2011, : 1844 - 1852
  • [30] Fast Flux Service Network Detection via Data Mining on Passive DNS Traffic
    Lombardo, Pierangelo
    Saeli, Salvatore
    Bisio, Federica
    Bernardi, Davide
    Massa, Danilo
    INFORMATION SECURITY (ISC 2018), 2018, 11060 : 463 - 480