Detecting Botnets By Analyzing Dns Traffic

Hao Tu,Zhi-Tang Li,Bin Liu
DOI: https://doi.org/10.1007/978-3-540-71549-8_40
2007-01-01
Abstract:Botnet is a new trend in Internet attacks. Because the propagation of botnets will not cause large traffic like worm, it is often difficult to detect it. Till now, the most common method to detect botnets is to use honeynets. Although previous work has described an active detection technique using DNS hijacking technique[1], there are little information about how to detect the domain names which botnets used. Some researchers also use DNS based method to detect botnets[2,3], but all of them use simple signature or statistical method which require much prior knowledge.
What problem does this paper attempt to address?