Title :
A framework for DNS based detection and mitigation of malware infections on a network
Author :
Stalmans, Etienne ; Irwin, Barry
Author_Institution :
Dept. of Comput. Sci., Rhodes Univ., Grahamstown, South Africa
Abstract :
Modern botnet trends have lead to the use of IP and domain fast-fluxing to avoid detection and increase resilience. These techniques bypass traditional detection systems such as blacklists and intrusion detection systems. The Domain Name Service (DNS) is one of the most prevalent protocols on modern networks and is essential for the correct operation of many network activities, including botnet activity. For this reason DNS forms the ideal candidate for monitoring, detecting and mitigating botnet activity. In this paper a system placed at the network edge is developed with the capability to detect fast-flux domains using DNS queries. Multiple domain features were examined to determine which would be most effective in the classification of domains. This is achieved using a C5.0 decision tree classifier and Bayesian statistics, with positive samples being labeled as potentially malicious and negative samples as legitimate domains. The system detects malicious domain names with a high degree of accuracy, minimising the need for blacklists. Statistical methods, namely Naive Bayesian, Bayesian, Total Variation distance and Probability distribution are applied to detect malicious domain names. The detection techniques are tested against sample traffic and it is shown that malicious traffic can be detected with low false positive rates.
Keywords :
Bayes methods; IP networks; computer network security; decision trees; invasive software; protocols; Bayesian statistics; Botnet activity; DNS based detection; DNS based mitigation; IP networks; Naive Bayesian; decision tree classifier; domain name service; intrusion detection systems; low false positive rates; malicious traffic; malware infections; network activities; probability distribution; total variation distance; Accuracy; Bayesian methods; Electronic mail; IP networks; Malware; Servers; Training data; Botnets; Domain Name Service; Security; Security Framework;
Conference_Titel :
Information Security South Africa (ISSA), 2011
Conference_Location :
Johannesburg
Print_ISBN :
978-1-4577-1481-8
DOI :
10.1109/ISSA.2011.6027531