DocumentCode :
1972668
Title :
Towards active measurement for DNS query behavior of botnets
Author :
Xiaobo Ma ; Jianfeng Li ; Jing Tao ; Xiaohong Guan
Author_Institution :
MOE KLINNS Lab., Xi´an Jiaotong Univ., Xi´an, China
fYear :
2012
fDate :
3-7 Dec. 2012
Firstpage :
845
Lastpage :
849
Abstract :
Domain names play an increasingly important role for the botnet activities. Traditionally, DNS traces from several local DNS servers are used passively to measure the DNS query behavior. However, since botnets are a wide-scale threat and usually reside in geographically dispersed networks, the vantage point of several local DNS servers is sometimes too small to help us understand the DNS query behavior (e.g., whether queried or not, average query rate) of botnets. In this paper, we actively measure the DNS query behavior of botnets in geographically dispersed networks via the DNS cache probing technique. We first analytically characterize how multiple domain names are queried by botnets in different networks under certain circumstances. Then, we actively measure real botnet samples in the wild to gain insight into how multiple domain names are queried by botnets in 480 geographically dispersed networks globally, and show that our analytical characterization well describes the DNS query behavior of the botnet samples. The active measurement technique can help to acquire extensive DNS query information in different networks and thus potentially facilitate various DNS-related research and applications.
Keywords :
Internet; cache storage; computer networks; query processing; DNS cache probing technique; active botnet DNS query behavior measurement; analytical characterization; botnet activities; domain names; geographically dispersed networks; local DNS servers; wide-scale threat; DNS cache probing; DNS probing; active measurement; botnet; domain names;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Global Communications Conference (GLOBECOM), 2012 IEEE
Conference_Location :
Anaheim, CA
ISSN :
1930-529X
Print_ISBN :
978-1-4673-0920-2
Electronic_ISBN :
1930-529X
Type :
conf
DOI :
10.1109/GLOCOM.2012.6503218
Filename :
6503218
Link To Document :
بازگشت