Abstract | ||
---|---|---|
IThe botnet is considered as a critical issue of the Internet due to its fast
growing mechanism and affect. Recently, Botnets have utilized the DNS and query
DNS server just like any legitimate hosts. In this case, it is difficult to
distinguish between the legitimate DNS traffic and illegitimate DNS traffic. It
is important to build a suitable solution for botnet detection in the DNS
traffic and consequently protect the network from the malicious Botnets
activities. In this paper, a simple mechanism is proposed to monitors the DNS
traffic and detects the abnormal DNS traffic issued by the botnet based on the
fact that botnets appear as a group of hosts periodically. The proposed
mechanism is also able to classify the DNS traffic requested by group of hosts
(group behavior) and single hosts (individual behavior), consequently detect
the abnormal domain name issued by the malicious Botnets. Finally, the
experimental results proved that the proposed mechanism is robust and able to
classify DNS traffic, and efficiently detects the botnet activity with average
detection rate of 89 percent. |
Year | Venue | Keywords |
---|---|---|
2009 | Clinical Orthopaedics and Related Research | group behavior |
Field | DocType | Volume |
Domain name,Computer security,Group behavior,Srizbi botnet,Computer science,Botnet,Domain Name System,Computer network,The Internet | Journal | abs/0911.0 |
ISSN | Citations | PageRank |
International Journal of Computer Science and Information
Security, IJCSIS, Vol. 6, No. 1, pp. 097-104, October 2009, USA | 2 | 0.38 |
References | Authors | |
0 | 4 |
Name | Order | Citations | PageRank |
---|---|---|---|
Ahmed M. Manasrah | 1 | 9 | 4.36 |
Awsan Hasan | 2 | 2 | 0.38 |
Omar Amer Abouabdalla | 3 | 4 | 2.16 |
Sureswaran Ramadass | 4 | 110 | 12.03 |