• DocumentCode
    3100546
  • Title

    Detecting Malicious Flux Service Networks through Passive Analysis of Recursive DNS Traces

  • Author

    Perdisci, Roberto ; Corona, Igino ; Dagon, David ; Lee, Wenke

  • Author_Institution
    Coll. of Comput., Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2009
  • fDate
    7-11 Dec. 2009
  • Firstpage
    311
  • Lastpage
    320
  • Abstract
    In this paper we propose a novel, passive approach for detecting and tracking malicious flux service networks. Our detection system is based on passive analysis of recursive DNS (RDNS) traffic traces collected from multiple large networks. Contrary to previous work, our approach is not limited to the analysis of suspicious domain names extracted from spam emails or precompiled domain blacklists. Instead, our approach is able to detect malicious flux service networks in-the-wild, i.e., as they are accessed by users who fall victims of malicious content advertised through blog spam, instant messaging spam, social Website spam, etc., beside email spam. We experiment with the RDNS traffic passively collected at two large ISP networks. Overall, our sensors monitored more than 2.5 billion DNS queries per day from millions of distinct source IPs for a period of 45 days. Our experimental results show that the proposed approach is able to accurately detect malicious flux service networks. Furthermore, we show how our passive detection and tracking of malicious flux service networks may benefit spam filtering applications.
  • Keywords
    Web sites; computer crime; unsolicited e-mail; ISP network; blog spam; detection system; instant messaging spam; malicious content; malicious flux service network; passive analysis; passive detection; precompiled domain blacklist; recursive DNS traffic traces; social Website spam; spam email; spam filtering; suspicious domain name; Application software; Availability; Computer networks; Computer security; Educational institutions; Information services; Internet; Monitoring; Scattering; Telecommunication traffic; Botnet Detection; Flux Networks; Recursive DNS;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2009. ACSAC '09. Annual
  • Conference_Location
    Honolulu, HI
  • ISSN
    1063-9527
  • Print_ISBN
    978-0-7695-3919-5
  • Type

    conf

  • DOI
    10.1109/ACSAC.2009.36
  • Filename
    5380685