BotCVD: Visual analysis of DNS traffic for botnet detection

被引:0
|
作者
机构
[1] College of Information Technical Science, Nankai University, Tianjin
[2] School of Mathematical Sciences, Peking University, Beijing
来源
Jiang, H. (hellojhl@163.com) | 1600年 / Advanced Institute of Convergence Information Technology卷 / 04期
关键词
Botnet detection; DNS traffic; Server-host pair; VAT; Visualize;
D O I
10.4156/AISS.vol4.issue8.32
中图分类号
学科分类号
摘要
Botnets become one of the serious threats to the Internet. In this paper, we design a light-weighted approach-BotCVD (Bot Cluster Visual Detector) to detect botnet by visually analyzing DNS traffic. To avoid the confusion of the normal DNS traffic, BotCVD analyzes the features of server-host pairs instead of single hosts. Since bots in the same botnet behave similarly in DNS queries, BotCVD visually cluster server-host pairs by computing the dissimilarity matrix of server-host pairs. Through an ordered dissimilarity image, BotCVD could clearly show botnet clusters and detect the infected hosts and malicious servers. Experimental results on real-world network traces merged with synthetic botnet traces indicate that BotCVD can (i) visualize botnet clusters and (ii) detect botnets with a high detection rate and a low false positive rate.
引用
收藏
页码:264 / 273
页数:9
相关论文
共 50 条
  • [31] A Novel Traffic Analysis Model for Botnet Discovery in Dynamic Network
    Panimalar, P.
    Rameshkumar, K.
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2019, 44 (04) : 3033 - 3042
  • [32] BOTNET DETECTION USING INDEPENDENT COMPONENT ANALYSIS
    Ibrahim, Wan Nur Hidayah
    Anuar, Mohd Syahid
    Selamat, Ali
    Krejcar, Ondrej
    IIUM ENGINEERING JOURNAL, 2022, 23 (01): : 95 - 115
  • [33] Botnet sequential activity detection with hybrid analysis
    Putra, Muhammad Aidiel Rachman
    Ahmad, Tohari
    Hostiadi, Dandy Pramana
    Ijtihadie, Royyana Muslim
    EGYPTIAN INFORMATICS JOURNAL, 2024, 25
  • [34] Characterizing Mobile Applications Through Analysis of DNS Traffic
    Jimenez-Berenguel, Andrea
    Moure-Garrido, Marta
    Garcia-Rubio, Carlos
    Campo, Celeste
    PROCEEDINGS OF THE INT'L ACM SYMPOSIUM ON PERFORMANCE EVALUATION OF WIRELESS AD HOC, SENSOR, & UBIQUITOUS NETWORKS, PE-WASUN 2023, 2023, : 69 - 76
  • [35] BotMark: Automated botnet detection with hybrid analysis of flow-based and graph-based traffic behaviors
    Wang, Wei
    Shang, Yaoyao
    He, Yongzhong
    Li, Yidong
    Liu, Jiqiang
    INFORMATION SCIENCES, 2020, 511 : 284 - 296
  • [36] A Deep Learning Approach for Botnet Detection Using Raw Network Traffic Data
    Shahhosseini, Mohaddeseh
    Mashayekhi, Hoda
    Rezvani, Mohsen
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2022, 30 (03)
  • [37] ARCHITECTURE FOR APPLYING DATA MINING AND VISUALIZATION ON NETWORK FLOW FOR BOTNET TRAFFIC DETECTION
    Shahrestani, Alireza
    Feily, Maryam
    Ahmad, Rodina
    Ramadass, Sureswaran
    PROCEEDINGS OF THE 2009 INTERNATIONAL CONFERENCE ON COMPUTER TECHNOLOGY AND DEVELOPMENT, VOL 1, 2009, : 33 - +
  • [38] A Deep Learning Approach for Botnet Detection Using Raw Network Traffic Data
    Mohaddeseh Shahhosseini
    Hoda Mashayekhi
    Mohsen Rezvani
    Journal of Network and Systems Management, 2022, 30
  • [39] DGA-based botnets detection using DNS traffic mining
    Manasrah, Ahmed M.
    Khdour, Thair
    Freehat, Raeda
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (05) : 2045 - 2061
  • [40] Botnet Detection Method Analysis on the Effect of Feature Extraction
    Jiang Jianguo
    Biao Qi
    Shi Zhixin
    Yan Wang
    Bin Lv
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 1882 - 1888