Botnet Detection by Monitoring Group Activities in DNS Traffic

作者: Hyunsang Choi , Hanwoo Lee , Heejo Lee , Hyogon Kim , None

DOI: 10.1109/CIT.2007.90

关键词:

摘要: … DNS in rallying process and the DNS traffic have unique features which we define as group activity. The DNS … botnet DNS traffic, we can detect botnet. There are a few study which use …

参考文章(9)
David Dagon, Cliff Changchun Zou, Wenke Lee, Modeling Botnet Propagation Using Time Zones. network and distributed system security symposium. ,(2006)
Paul Barford, Vinod Yegneswaran, An Inside Look at Botnets Advances in Information Security. pp. 171- 191 ,(2007) , 10.1007/978-0-387-44599-1_8
Suresh Singh, James R. Binkley, An algorithm for anomaly-based botnet detection conference on steps to reducing unwanted traffic on internet. pp. 7- 7 ,(2006)
Farnam Jahanian, Danny McPherson, Evan Cooke, The Zombie roundup: understanding, detecting, and disrupting botnets conference on steps to reducing unwanted traffic on internet. pp. 6- 6 ,(2005)
David Dagon, Nick Feamster, Anirudh Ramachandran, Revealing botnet membership using DNSBL counter-intelligence conference on steps to reducing unwanted traffic on internet. pp. 8- 8 ,(2006)
J. Oikarinen, D. Reed, Internet Relay Chat Protocol RFC. ,vol. 1459, pp. 1- 65 ,(1993)
Moheeb Abu Rajab, Jay Zarfoss, Fabian Monrose, Andreas Terzis, A multifaceted approach to understanding the botnet phenomenon internet measurement conference. pp. 41- 52 ,(2006) , 10.1145/1177080.1177086
J. Bound, S. Thomson, Y. Rekhter, P. Vixie, Dynamic Updates in the Domain Name System (DNS UPDATE) RFC 2136. ,vol. 2136, pp. 1- 26 ,(1997)
John Kristoff, Rodney Joffee, Botnets and Packet Flooding DDoS Attacks on the Domain Name System The International Journal of Forensic Computer Science. pp. 9- 18 ,(2007) , 10.5769/J200701001