Issues and challenges in DNS based botnet detection: A survey

被引:47
|
作者
Singh, Manmeet [1 ,2 ]
Singh, Maninder [1 ]
Kaur, Sanmeet [1 ]
机构
[1] Thapar Univ, Comp Sci & Engn Dept, Patiala, Punjab, India
[2] Baba Ghulam Shah Badshah Univ, Dept Informat Technol & Engn, Rajouri, Jammu & Kashmir, India
关键词
Botnet; Botnet detection; DNS-based Botnet detection; Network Security; DGA; CYBERCRIME; ATTACKS;
D O I
10.1016/j.cose.2019.05.019
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybercrimes are evolving on a regular basis and as such these crimes are becoming a greater threat day by day. Earlier these threats were very general and unorganized. In the last decade, these attacks have become highly sophisticated in nature. This higher level of coordination is possible mainly due to botnets, which are clusters of infected hosts controlled remotely by an attacker (botmaster). The number of infected machines is continuously rising, thereby resulting in botnets with over a million infected machines. This powerful capability gives the botmaster a lethal weapon to launch various security attacks. As a result, botnet detection techniques received greater research focus. The Domain Name System (DNS) is a large scale distributed database on the Internet, which is being abused as a botnet communication channel. While there are numerous survey and review papers on botnet detection, there are two survey papers on DNS-based botnet detection which are neither comprehensive nor take into consideration various parameters vital for effective comparison. This survey presents a new classification for DNS-based botnet detection techniques and provides a deep analysis of each technique within the category. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:28 / 52
页数:25
相关论文
共 50 条
  • [1] A survey of botnet detection based on DNS
    Alieyan, Kamal
    ALmomani, Ammar
    Manasrah, Ahmad
    Kadhum, Mohammed M.
    NEURAL COMPUTING & APPLICATIONS, 2017, 28 (07) : 1541 - 1558
  • [2] A survey of botnet detection based on DNS
    Kamal Alieyan
    Ammar ALmomani
    Ahmad Manasrah
    Mohammed M. Kadhum
    Neural Computing and Applications, 2017, 28 : 1541 - 1558
  • [3] Botnet Detection Technology Based on DNS
    Li, Xingguo
    Wang, Junfeng
    Zhang, Xiaosong
    FUTURE INTERNET, 2017, 9 (04)
  • [4] DNS rule-based schema to botnet detection
    Alieyan, Kamal
    Almomani, Ammar
    Anbar, Mohammed
    Alauthman, Mohammad
    Abdullah, Rosni
    Gupta, B. B.
    ENTERPRISE INFORMATION SYSTEMS, 2021, 15 (04) : 545 - 564
  • [5] A Survey of Botnet and Botnet Detection
    Feily, Maryam
    Shahrestani, Alireza
    Ramadass, Sureswaran
    2009 THIRD INTERNATIONAL CONFERENCE ON EMERGING SECURITY INFORMATION, SYSTEMS, AND TECHNOLOGIES, 2009, : 268 - +
  • [6] IoT Botnet Detection Based on the Behaviors of DNS Queries
    Fan, Chun-I
    Shie, Cheng-Han
    Hsu, Che-Ming
    Ban, Tao
    Morikawa, Tomohiro
    Takahashi, Takeshi
    2022 5TH IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (IEEE DSC 2022), 2022,
  • [7] BOTNET DETECTION BASED ON DNS RECORDS AND ACTIVE PROBING
    Prieto, Iria
    Magana, Eduardo
    Morato, Daniel
    Izal, Mikel
    SECRYPT 2011: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2011, : 307 - 316
  • [8] A Survey on Botnet: Classification, Detection and Defense
    Amini, Pedram
    Araghizadeh, Muhammad Amin
    Azmi, Reza
    2015 INTERNATIONAL ELECTRONICS SYMPOSIUM (IES), 2015, : 233 - 238
  • [9] A Technique for the Botnet Detection Based on DNS-Traffic Analysis
    Pomorova, Oksana
    Savenko, Oleg
    Lysenko, Sergii
    Kryshchuk, Andrii
    Bobrovnikova, Kira
    COMPUTER NETWORKS, CN 2015, 2015, 522 : 127 - 138
  • [10] A Review of Botnet Detection Approaches Based on DNS Traffic Analysis
    Al-Mashhadi, Saif
    Anbar, Mohammed
    Karuppayah, Shankar
    Al-Ani, Ahmed K.
    INTELLIGENT AND INTERACTIVE COMPUTING, 2019, 67 : 305 - 321