Detection of Domain-flux Botnet Domain Names

LI Qing-shan,CHEN Zhong
DOI: https://doi.org/10.3969/j.issn.1000-7024.2012.08.004
2012-01-01
Abstract:Aimed at the shortage of current detection methods of domain-flux botnet,a method based on the alive character of domain name is proposed.The description of domains alive character is given which are generated by domain-flux botnet,and an domain-flux botnet detection method based on the alive characteristics of domain names is proposed.The detection description,detection flow and system structure are introduced.An experiment using the mirror dns traffic from an service provider is designed to validate the effectiveness of this detection method.The result shows that the method proposed do not rely on specific alphanumeric characteristics of domain names,and could find domain names efficiently used by domain-flux botnet.
What problem does this paper attempt to address?