Back to Search
Start Over
Phoenix: DGA-Based Botnet Tracking and Intelligence
- Source :
- Detection of Intrusions and Malware, and Vulnerability Assessment ISBN: 9783319085081, DIMVA
- Publication Year :
- 2014
- Publisher :
- Springer International Publishing, 2014.
-
Abstract
- Modern botnets rely on domain-generation algorithms (DGAs) to build resilient command-and-control infrastructures. Given the prevalence of this mechanism, recent work has focused on the analysis of DNS traffic to recognize botnets based on their DGAs. While previous work has concentrated on detection, we focus on supporting intelligence operations. We propose Phoenix, a mechanism that, in addition to telling DGA- and non-DGA-generated domains apart using a combination of string and IP-based features, characterizes the DGAs behind them, and, most importantly, finds groups of DGA-generated domains that are representative of the respective botnets. As a result, Phoenix can associate previously unknown DGA-generated domains to these groups, and produce novel knowledge about the evolving behavior of each tracked botnet. We evaluated Phoenix on 1,153,516 domains, including DGA-generated domains from modern, well-known botnets: without supervision, it correctly distinguished DGA- vs. non-DGA-generated domains in 94.8 percent of the cases, characterized families of domains that belonged to distinct DGAs, and helped researchers “on the field” in gathering intelligence on suspicious domains to identify the correct botnet.
- Subjects :
- DBSCAN
Domain generation algorithm
biology
Computer science
business.industry
String (computer science)
Botnet
biology.organism_classification
Machine learning
computer.software_genre
Computer security
Field (computer science)
Tracking (education)
Artificial intelligence
Phoenix
business
computer
Subjects
Details
- ISBN :
- 978-3-319-08508-1
- ISBNs :
- 9783319085081
- Database :
- OpenAIRE
- Journal :
- Detection of Intrusions and Malware, and Vulnerability Assessment ISBN: 9783319085081, DIMVA
- Accession number :
- edsair.doi.dedup.....9ae15d4798cfe574a2ee3b10c588829c
- Full Text :
- https://doi.org/10.1007/978-3-319-08509-8_11