BotCVD: Visual analysis of DNS traffic for botnet detection

被引:0
|
作者
机构
[1] College of Information Technical Science, Nankai University, Tianjin
[2] School of Mathematical Sciences, Peking University, Beijing
来源
Jiang, H. (hellojhl@163.com) | 1600年 / Advanced Institute of Convergence Information Technology卷 / 04期
关键词
Botnet detection; DNS traffic; Server-host pair; VAT; Visualize;
D O I
10.4156/AISS.vol4.issue8.32
中图分类号
学科分类号
摘要
Botnets become one of the serious threats to the Internet. In this paper, we design a light-weighted approach-BotCVD (Bot Cluster Visual Detector) to detect botnet by visually analyzing DNS traffic. To avoid the confusion of the normal DNS traffic, BotCVD analyzes the features of server-host pairs instead of single hosts. Since bots in the same botnet behave similarly in DNS queries, BotCVD visually cluster server-host pairs by computing the dissimilarity matrix of server-host pairs. Through an ordered dissimilarity image, BotCVD could clearly show botnet clusters and detect the infected hosts and malicious servers. Experimental results on real-world network traces merged with synthetic botnet traces indicate that BotCVD can (i) visualize botnet clusters and (ii) detect botnets with a high detection rate and a low false positive rate.
引用
收藏
页码:264 / 273
页数:9
相关论文
共 50 条
  • [1] A Technique for the Botnet Detection Based on DNS-Traffic Analysis
    Pomorova, Oksana
    Savenko, Oleg
    Lysenko, Sergii
    Kryshchuk, Andrii
    Bobrovnikova, Kira
    COMPUTER NETWORKS, CN 2015, 2015, 522 : 127 - 138
  • [2] Holistic Model for HTTP Botnet Detection Based on DNS Traffic Analysis
    Alenazi, Abdelraman
    Traore, Issa
    Ganame, Karim
    Woungang, Isaac
    INTELLIGENT, SECURE, AND DEPENDABLE SYSTEMS IN DISTRIBUTED AND CLOUD ENVIRONMENTS (ISDDC 2017), 2017, 10618 : 1 - 18
  • [3] PsyBoG: A scalable botnet detection method for large-scale DNS traffic
    Kwon, Jonghoon
    Lee, Jehyun
    Lee, Heejo
    Perrig, Adrian
    COMPUTER NETWORKS, 2016, 97 : 48 - 73
  • [4] A survey of botnet detection based on DNS
    Alieyan, Kamal
    ALmomani, Ammar
    Manasrah, Ahmad
    Kadhum, Mohammed M.
    NEURAL COMPUTING & APPLICATIONS, 2017, 28 (07) : 1541 - 1558
  • [5] A survey of botnet detection based on DNS
    Kamal Alieyan
    Ammar ALmomani
    Ahmad Manasrah
    Mohammed M. Kadhum
    Neural Computing and Applications, 2017, 28 : 1541 - 1558
  • [6] Detecting DGA-Based Botnet with DNS Traffic Analysis in Monitored Network
    Dinh-Tu Truong
    Cheng, Guang
    Jakalan, Ahmad
    Guo, Xiaojun
    Zhou, Aiping
    JOURNAL OF INTERNET TECHNOLOGY, 2016, 17 (02): : 217 - 230
  • [7] Peer-to-Peer BotNet Traffic Analysis and Detection
    Han, Dongseok
    Han, Kyoung Soo
    Kang, Boojoong
    Han, Hwansoo
    Im, Eul Gyu
    INFORMATION-AN INTERNATIONAL INTERDISCIPLINARY JOURNAL, 2012, 15 (04): : 1605 - 1624
  • [8] DFBotKiller: Domain-flux botnet detection based on the history of group activities and failures in DNS traffic
    Sharifnya, Reza
    Abadi, Mahdi
    DIGITAL INVESTIGATION, 2015, 12 : 15 - 26
  • [9] Hybrid rule-based botnet detection approach using machine learning for analysing DNS traffic
    Al-Mashhadi, Saif
    Anbar, Mohammed
    Hasbullah, Iznan
    Alamiedy, Taief Alaa
    PEERJ COMPUTER SCIENCE, 2021, 7 : 1 - 34
  • [10] DNS rule-based schema to botnet detection
    Alieyan, Kamal
    Almomani, Ammar
    Anbar, Mohammed
    Alauthman, Mohammad
    Abdullah, Rosni
    Gupta, B. B.
    ENTERPRISE INFORMATION SYSTEMS, 2021, 15 (04) : 545 - 564