DocumentCode
3768290
Title
Botnet Domain Name Detection based on machine learning
Author
Jian Jin;Zhiwei Yan;Guanggang Geng;Baoping Yan
Author_Institution
China Internet Network Information Center, Beijing 100190, China
fYear
2015
Firstpage
273
Lastpage
276
Abstract
Domain Name System (DNS) is a fundamental component of today´s Internet: it provides mappings between domain names used by people and the corresponding IP addresses required by network protocols. However, the open and fundamental characteristics of DNS are recently used by the botnet for the communication between bots and C&C. In this paper, we select six kinds of special features of botnet domain querying traffic based on the deep studies of the DNS log. Then three popular classifiers are adopted in order to pick the malicious domains out from the DNS traffic using those features.
Publisher
iet
Conference_Titel
Wireless, Mobile and Multi-Media (ICWMMN 2015), 6th International Conference on
Print_ISBN
978-1-78561-046-2
Type
conf
DOI
10.1049/cp.2015.0953
Filename
7453917
Link To Document