Open Access
Subscription Access
Detecting DGA-Based Botnet with DNS Traffic Analysis in Monitored Network
Abstract
Modern botnets such as Zeus, Conficker have started employing a technique called domain fluxing to prevent a naive blacklisting approach employed by network administrators. Domain fluxing bots generate a list of Pseudo-Random Domain names (PRD) or base on a predefined algorithm, called Domain name Generation Algorithm (DGA) for botnet operators to command and control (C&C) their bots. It is a pressing issue today to prevent or least reduce their destructive actions. In this paper, we focus on detecting domain-flux botnet within the monitored network based on DNS traffic features. First, we present a method to identify bot-infected machines based on the similar periodic time intervals series of DNS queries. Then, in order to detect C&C Server, we monitor the stream of active DNS queries from bot-infected machines, and introduce a method to extract related feature values aiming to distinguish bot-generated domain names from humangenerated ones base on a classifier model that we previously trained. We use five various machine learning algorithms to train classifier models and evaluate the effectiveness of detection. The experimental results showed that the proposed method achieves the highest detection efficiency for decision trees algorithms (J48) with the average overall accuracy up to 98.5% and false positive rate is 1.2%.
Keywords
Domain-flux; DGA-based botnet; Malicious domains; Botnet detection
Citation Format:
Dinh-Tu Truong, Guang Cheng, Ahmad Jakalan, Xiao-Jun Guo, Ai-Ping Zhou, "Detecting DGA-Based Botnet with DNS Traffic Analysis in Monitored Network," Journal of Internet Technology, vol. 17, no. 2 , pp. 217-230, Mar. 2016.
Dinh-Tu Truong, Guang Cheng, Ahmad Jakalan, Xiao-Jun Guo, Ai-Ping Zhou, "Detecting DGA-Based Botnet with DNS Traffic Analysis in Monitored Network," Journal of Internet Technology, vol. 17, no. 2 , pp. 217-230, Mar. 2016.
Full Text:
PDFRefbacks
- There are currently no refbacks.
Published by Executive Committee, Taiwan Academic Network, Ministry of Education, Taipei, Taiwan, R.O.C
JIT Editorial Office, Office of Library and Information Services, National Dong Hwa University
No. 1, Sec. 2, Da Hsueh Rd., Shoufeng, Hualien 974301, Taiwan, R.O.C.
Tel: +886-3-931-7314 E-mail: jit.editorial@gmail.com