• DocumentCode
    592103
  • Title

    Formulistic Detection of Malicious Fast-Flux Domains

  • Author

    Chia-Mei Chen ; Sheng-Tzong Cheng ; Ju-Hsien Chou ; Ya-Hui Ou

  • Author_Institution
    Dept. of Inf. Manage., Nat. Sun Yat-sen Univ., Kaohsiung, Taiwan
  • fYear
    2012
  • fDate
    17-20 Dec. 2012
  • Firstpage
    72
  • Lastpage
    79
  • Abstract
    Botnet creates harmful network attacks nowadays. Lawbreaker may implant malware into victim machines using botnets and, furthermore, he employs fast-flux domain technology to improve the lifetime of botnets. To circumvent the detection of command and control server, a set of bots are selected to redirect malicious communication and hides botnet communication within normal user traffic. As the dynamics of fast-flux domains, blacklist mechanism is not efficient to prevent fast-flux botnet attacks. It would be time consuming to examine the legitimacy of the domain of all the network connections. Therefore, a lightweight detection of malicious fast-flux domains is desired. Based on the time-space behavior of malicious fast-flux domains, the network behavior of domains are formulistic in this study to reduce the time complexity of feature modeling. According to the experimental results, the malicious fast-flux domains collected from real networks are identified efficiently and the proposed solution outperforms the blacklists.
  • Keywords
    computational complexity; computer network security; invasive software; network servers; telecommunication traffic; blacklist mechanism; botnets lifetime; command and control server; domain legitimacy; fast-flux botnet attacks; feature modeling; formulistic detection; lawbreaker; lightweight detection; malicious communication; malicious fast-flux domains; malware; network attacks; network connections; time complexity; time-space behavior; victim machines; IP networks; Organizations; Registers; Security; Twitter; Web servers; Botnet; command and control server; fast-flux domain; malware;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Parallel Architectures, Algorithms and Programming (PAAP), 2012 Fifth International Symposium on
  • Conference_Location
    Taipei
  • ISSN
    2168-3034
  • Print_ISBN
    978-1-4673-4566-8
  • Type

    conf

  • DOI
    10.1109/PAAP.2012.19
  • Filename
    6424739