• DocumentCode
    3768290
  • Title

    Botnet Domain Name Detection based on machine learning

  • Author

    Jian Jin;Zhiwei Yan;Guanggang Geng;Baoping Yan

  • Author_Institution
    China Internet Network Information Center, Beijing 100190, China
  • fYear
    2015
  • Firstpage
    273
  • Lastpage
    276
  • Abstract
    Domain Name System (DNS) is a fundamental component of today´s Internet: it provides mappings between domain names used by people and the corresponding IP addresses required by network protocols. However, the open and fundamental characteristics of DNS are recently used by the botnet for the communication between bots and C&C. In this paper, we select six kinds of special features of botnet domain querying traffic based on the deep studies of the DNS log. Then three popular classifiers are adopted in order to pick the malicious domains out from the DNS traffic using those features.
  • Publisher
    iet
  • Conference_Titel
    Wireless, Mobile and Multi-Media (ICWMMN 2015), 6th International Conference on
  • Print_ISBN
    978-1-78561-046-2
  • Type

    conf

  • DOI
    10.1049/cp.2015.0953
  • Filename
    7453917