Mostrar el registro sencillo del ítem

dc.contributor.authorYadav, Sandeep
dc.contributor.authorKumar Reddy, Ashwath
dc.contributor.authorNarasimha Reddy, A.L. 
dc.contributor.authorRanjan, Supranamaya
dc.date.accessioned2021-07-13T10:07:19Z
dc.date.available2021-07-13T10:07:19Z
dc.date.issued2010-11-01
dc.identifier.urihttp://hdl.handle.net/20.500.12761/1263
dc.description.abstractRecent Botnets such as Conficker, Kraken and Torpig have used DNS based “domain fluxing” for command-and-control, where each Bot queries for existence of a series of domain names and the owner has to register only one such domain name. In this paper, we develop a methodology to detect such “domain fluxes” in DNS traffic by looking for patterns inherent to domain names that are generated algorithmically, in contrast to those generated by humans. In particular, we look at distribution of alphanumeric characters as well as bigrams in all domains that are mapped to the same set of IP-addresses. We present and compare the performance of several distance metrics, including KL-distance, Edit distance and Jaccard measure. We train by using a good data set of domains obtained via a crawl of domains mapped to all IPv4 address space and modeling bad data sets based on behaviors seen so far and expected. We also apply our methodology to packet traces collected at a Tier-1 ISP and show we can automatically detect domain fluxing as used by Conficker botnet with minimal false positives
dc.language.isoeng
dc.subject.lccQ Science::Q Science (General)
dc.subject.lccQ Science::QA Mathematics::QA75 Electronic computers. Computer science
dc.subject.lccT Technology::T Technology (General)
dc.subject.lccT Technology::TA Engineering (General). Civil engineering (General)
dc.subject.lccT Technology::TK Electrical engineering. Electronics Nuclear engineering
dc.titleDetecting algorithmically generated malicious domain namesen
dc.typeconference object
dc.conference.date1-3 November 2010
dc.conference.placeMelbourne, Australia
dc.conference.titleInternet Measurement Conference 2010*
dc.event.typeconference
dc.pres.typepaper
dc.type.hasVersionVoR
dc.rights.accessRightsopen access
dc.description.refereedTRUE
dc.description.statuspub
dc.eprint.idhttp://eprints.networks.imdea.org/id/eprint/67


Ficheros en el ítem

Este ítem aparece en la(s) siguiente(s) colección(ones)

Mostrar el registro sencillo del ítem