Classification of DNS Queries for Anomaly Detection

Hongbo Shi,Kazuhiko Iwasaki
DOI: https://doi.org/10.1109/PRDC.2013.27
2013-01-01
Abstract:We propose a new method that uses a neural network, the Growing Hierarchical Self-Organizing Map (GHSOM), to analyze the DNS query log files. Due to the structure of the DNS query frequency, infected computers are easy to detect. Our experiment shows the different DNS query structure between healthy and infected computers.
What problem does this paper attempt to address?