• DocumentCode
    621136
  • Title

    Trapping botnets by DNS failure graphs: Validation, extension and application to a 3G network

  • Author

    Bar, Arian ; Paciello, Antonio ; Romirer-Maierhofer, Peter

  • Author_Institution
    Forschungszentrum Telekommunikation Wien (FTW), Vienna, Austria
  • fYear
    2013
  • fDate
    14-19 April 2013
  • Firstpage
    393
  • Lastpage
    398
  • Abstract
    In the last years, botnets have become one of the major sources of cyber-crime activities carried out via the public Internet. Typically, they may serve a number of different malicious activities such as Distributed Denial of Service (DDoS) attacks, email spam and phishing attacks. In this paper we validate the Domain Name System (DNS) failure graph approach presented earlier in [1]. In our work we apply this approach in an operational 3G mobile network serving a significantly larger user population.Based on the introduction of stable host identifiers we implement a novel approach to the tracking of botnets over a period of several weeks. Our results reveal the presence of several groups of hosts that are members of botnets. We analyze the host groups exhibiting the most suspicious behavior and elaborate on how these participate in botnets and other malicious activities. In the last part of this work we discuss how the accuracy of our detection approach could be improved in the future by correlating the knowledge obtained from applying our method in different networks.
  • Keywords
    3G mobile communication; Internet; computer crime; computer network security; graph theory; DDoS attacks; DNS failure graphs; Distributed Denial of Service attacks; Domain Name System failure graph approach; botnet tracking; botnet trapping; cyber-crime activities; email spam; host identifiers; malicious activities; operational 3G mobile network; phishing attacks; public Internet; Algorithm design and analysis; Clustering algorithms; Electronic mail; IP networks; Monitoring; Servers; Superluminescent diodes;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications Workshops (INFOCOM WKSHPS), 2013 IEEE Conference on
  • Conference_Location
    Turin
  • Print_ISBN
    978-1-4799-0055-8
  • Type

    conf

  • DOI
    10.1109/INFCOMW.2013.6562863
  • Filename
    6562863