Title :
Formulistic Detection of Malicious Fast-Flux Domains
Author :
Chia-Mei Chen ; Sheng-Tzong Cheng ; Ju-Hsien Chou ; Ya-Hui Ou
Author_Institution :
Dept. of Inf. Manage., Nat. Sun Yat-sen Univ., Kaohsiung, Taiwan
Abstract :
Botnet creates harmful network attacks nowadays. Lawbreaker may implant malware into victim machines using botnets and, furthermore, he employs fast-flux domain technology to improve the lifetime of botnets. To circumvent the detection of command and control server, a set of bots are selected to redirect malicious communication and hides botnet communication within normal user traffic. As the dynamics of fast-flux domains, blacklist mechanism is not efficient to prevent fast-flux botnet attacks. It would be time consuming to examine the legitimacy of the domain of all the network connections. Therefore, a lightweight detection of malicious fast-flux domains is desired. Based on the time-space behavior of malicious fast-flux domains, the network behavior of domains are formulistic in this study to reduce the time complexity of feature modeling. According to the experimental results, the malicious fast-flux domains collected from real networks are identified efficiently and the proposed solution outperforms the blacklists.
Keywords :
computational complexity; computer network security; invasive software; network servers; telecommunication traffic; blacklist mechanism; botnets lifetime; command and control server; domain legitimacy; fast-flux botnet attacks; feature modeling; formulistic detection; lawbreaker; lightweight detection; malicious communication; malicious fast-flux domains; malware; network attacks; network connections; time complexity; time-space behavior; victim machines; IP networks; Organizations; Registers; Security; Twitter; Web servers; Botnet; command and control server; fast-flux domain; malware;
Conference_Titel :
Parallel Architectures, Algorithms and Programming (PAAP), 2012 Fifth International Symposium on
Conference_Location :
Taipei
Print_ISBN :
978-1-4673-4566-8
DOI :
10.1109/PAAP.2012.19