Detecting Algorithmically Generated Malicious Domain Names
Source: Association for Computing Machinery
Recent Botnets such as Conficker, Kraken and Torpig have used DNS based "Domain fluxing" for command-and-control, where each Bot queries for existence of a series of domain names and the owner has to register only one such domain name. In this paper, the authors develop a methodology to detect such "Domain fluxes" in DNS traffic by looking for patterns inherent to domain names that are generated algorithmically, in contrast to those generated by humans. In particular, they look at distribution of alphanumeric characters as well as bigrams in all domains that are mapped to the same set of IP-addresses.
| Format: | Size: | 264.40 | |
| Date: | Nov 2010 |
People who downloaded this item also downloaded
- Collaborative Detection of Fast Flux Phishing Domains
- Preprocessing DNS Log Data for Effective Data Mining



