...
首页> 外文期刊>International journal of software engineering and knowledge engineering >Detecting Domain-Flux Malware Using DNS Failure Traffic
【24h】

Detecting Domain-Flux Malware Using DNS Failure Traffic

机译:使用DNS故障流量检测域流量恶意软件

获取原文
获取原文并翻译 | 示例
           

摘要

Domain-Flux malware is hard to detect because of the variable C&C (Command and Control) domains which were randomly generated by the technique of domain generation algorithm (DGA). In this paper, we propose a Domain-Flux malware detection approach based on DNS failure traffic. The approach fully leverages the behavior of DNS failure traffic to recognize nine features, and then mines the DGA-generated domains by a clustering algorithm and determinable rules. Theoretical analysis and experimental results verify its efficiency with both test dataset and real-world dataset. On the test dataset, our approach can achieve a true positive rate of 99.82% at false positive rate of 0.39%. On the real-world dataset, the approach can also achieve a relatively high precision of 98.3% and find out 197,026 DGA domains by analyzing DNS traffic in campus network for seven days. We found 1213 hosts of Domain-Flux malware existing on campus network, including the known Conficker, Fosniw and several new Domain-Flux malwares that have never been reported before. We classified 197,026 DGA domains and gave the representative generated patterns for a better understanding of the Domain-Flux mechanism.
机译:Domain-Flux恶意软件很难检测,因为可变的C&C(命令和控制)域是通过域生成算法(DGA)技术随机生成的。在本文中,我们提出了一种基于DNS故障流量的Domain-Flux恶意软件检测方法。该方法充分利用DNS故障流量的行为来识别九种功能,然后通过聚类算法和可确定的规则挖掘DGA生成的域。理论分析和实验结果均通过测试数据集和实际数据集验证了其效率。在测试数据集上,我们的方法可以在0.39%的假阳性率下实现99.82%的真实阳性率。在现实世界的数据集上,该方法还可以通过分析校园网络中的DNS流量7天来达到98.3%的相对较高的精度,并找出197,026个DGA域。我们发现校园网络中存在1213台Domain-Flux恶意软件主机,其中包括已知的Conficker,Fosniw和一些以前从未报告过的新的Domain-Flux恶意软件。我们对197,026个DGA域进行了分类,并给出了代表生成的模式,以更好地了解Domain-Flux机制。

著录项

  • 来源
  • 作者单位

    School of Cyberspace Security, Shanghai Jiao Tong University Shanghai 200240, P. R. China;

    School of Cyberspace Security, Shanghai Jiao Tong University Shanghai 200240, P. R. China;

    School of Cyberspace Security, Shanghai Jiao Tong University Shanghai 200240, P. R. China;

    School of Cyberspace Security, Shanghai Jiao Tong University Shanghai 200240, P. R. China;

    Network and Information Center, Shanghai Jiao Tong University Shanghai 200240, P. R. China;

    Network and Information Center, Shanghai Jiao Tong University Shanghai 200240, P. R. China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    DGA; DNS; malware detection; clustering; failure traffic;

    机译:DGA;DNS;恶意软件检测;集群故障流量;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号