DocumentCode :
1966950
Title :
Real-Time Fast-Flux Identification via Localized Spatial Geolocation Detection
Author :
Wang, Horng-Tzer ; Mao, Ching-Hao ; Wu, Kuo-Ping ; Lee, Hahn-Ming
Author_Institution :
Dept. of Comput. Sci. & Inf. Eng., Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
fYear :
2012
fDate :
16-20 July 2012
Firstpage :
244
Lastpage :
252
Abstract :
Fast-flux service networks (FFSNs), broadly used by botnets, are an evasive technique for conducting malicious behavior via rapid activities. FFSN detection easily fails in the case of poor performance and causes a high incidence of false positives due to the similarity of an FFSN to a content distribution network (CDN), a normal behavior for load balance. In this study, we propose a localized spatial geolocation detection (LSGD) system for identifying FFSNs in real time. We believe that the grid distribution of LSGD possesses a precise spatial locating capability for profiling the spatial relations between IP address resolutions. Furthermore, autonomous system numbers (ASNs) are used for enhancing localized geographic characteristics. The proposed system, incorporating LSGD, ASNs, and the domain name system (DNS), can respond well to identify potential FFSNs. The results of our experiment show that the proposed LSGD system has a better detection capability than state-of-the-art spatial or temporal detection approaches, with a lower false positive rate in real-time detection than the approach based on a spatial snapshot alone.
Keywords :
IP networks; Internet; computer network security; geography; resource allocation; ASN; CDN; DNS; FFSN detection; IP address resolutions; LSGD; autonomous system numbers; botnets; content distribution network; domain name system; fast-flux service networks; grid distribution; load balance; localized spatial geolocation detection; malicious behavior; real-time fast-flux identification; spatial detection approach; spatial locating capability; temporal detection approach; Delay; Engines; Entropy; Feature extraction; Geology; IP networks; Real-time systems; Bayesian network; Botnet; Content Distribution Network (CDN); Fast-flux Service Network(FFSN); spatial detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications Conference (COMPSAC), 2012 IEEE 36th Annual
Conference_Location :
Izmir
ISSN :
0730-3157
Print_ISBN :
978-1-4673-1990-4
Electronic_ISBN :
0730-3157
Type :
conf
DOI :
10.1109/COMPSAC.2012.35
Filename :
6340149
Link To Document :
بازگشت