Skip to main content
Erschienen in:
Buchtitelbild

2017 | OriginalPaper | Buchkapitel

Holistic Model for HTTP Botnet Detection Based on DNS Traffic Analysis

verfasst von : Abdelraman Alenazi, Issa Traore, Karim Ganame, Isaac Woungang

Erschienen in: Intelligent, Secure, and Dependable Systems in Distributed and Cloud Environments

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

HTTP botnets are currently the most popular form of botnets compared to IRC and P2P botnets. This is because, they are not only easier to implement, operate, and maintain, but they can easily evade the detection. Likewise, HTTP botnets flows can easily be buried in the huge volume of legitimate HTTP traffic occurring in many organizations, which makes the detection harder. In this paper, a new detection framework involving three detection models is proposed, which can run independently or in tandem. The first detector profiles the individual applications based on their interactions, and isolates accordingly the malicious ones. The second detector tracks the regularity in the timing of the bot DNS queries, and uses this as basis for detection. The third detector analyzes the characteristics of the domain names involved in the DNS, and identifies the algorithmically generated and fast flux domains, which are staples of typical HTTP botnets. Several machine learning classifiers are investigated for each of the detectors. Experimental evaluation using public datasets and datasets collected in our testbed yield very encouraging performance results.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Fußnoten
1
Short life refers the time interval between two queries of the same domain.
.
 
Literatur
1.
Zurück zum Zitat Antonakakis, M., Perdisci, R., Dagon D., Lee W., Feamster, N.: Building a dynamic reputation system for DNS. In: The Proceedings of 19th USENIX Security Symposium (USENIX Security 2010) (2010) Antonakakis, M., Perdisci, R., Dagon D., Lee W., Feamster, N.: Building a dynamic reputation system for DNS. In: The Proceedings of 19th USENIX Security Symposium (USENIX Security 2010) (2010)
2.
Zurück zum Zitat Bilge, L., Sen, S., Balzarotti, D., Kirda, E., Kruegel, C.: Exposure: a passive DNS analysis service to detect and report malicious domains. ACM Trans. Inf. Syst. Secur. (TISSEC) 16(4), 14 (2014)CrossRef Bilge, L., Sen, S., Balzarotti, D., Kirda, E., Kruegel, C.: Exposure: a passive DNS analysis service to detect and report malicious domains. ACM Trans. Inf. Syst. Secur. (TISSEC) 16(4), 14 (2014)CrossRef
3.
Zurück zum Zitat Cai, T., Zou, F.: Detecting HTTP botnet with clustering network traffic. In: Proceedings of the 8th Conference Wireless Communications, Networking and Mobile Computing, pp. 1–7, September 2012 Cai, T., Zou, F.: Detecting HTTP botnet with clustering network traffic. In: Proceedings of the 8th Conference Wireless Communications, Networking and Mobile Computing, pp. 1–7, September 2012
4.
Zurück zum Zitat Chaware, S.P., Bhingarkar, S.: A survey of HTTP botnet detection. Int. Res. J. Eng. Technol. (IRJET) 3(1), 713–714 (2016) Chaware, S.P., Bhingarkar, S.: A survey of HTTP botnet detection. Int. Res. J. Eng. Technol. (IRJET) 3(1), 713–714 (2016)
5.
Zurück zum Zitat da Luz, P.M.: Botnet detection using passive DNS. Master thesis, Department of Computing Science Radboud University Nijmegen (2013/2014) da Luz, P.M.: Botnet detection using passive DNS. Master thesis, Department of Computing Science Radboud University Nijmegen (2013/2014)
6.
Zurück zum Zitat Fedynyshyn, G., Chuah, M.C., Tan, G.: Detection and classification of different botnet C&C channels. In: Calero, J.M.A., Yang, L.T., Mármol, F.G., García Villalba, L.J., Li, A.X., Wang, Y. (eds.) ATC 2011. LNCS, vol. 6906, pp. 228–242. Springer, Heidelberg (2011). doi:10.1007/978-3-642-23496-5_17 CrossRef Fedynyshyn, G., Chuah, M.C., Tan, G.: Detection and classification of different botnet C&C channels. In: Calero, J.M.A., Yang, L.T., Mármol, F.G., García Villalba, L.J., Li, A.X., Wang, Y. (eds.) ATC 2011. LNCS, vol. 6906, pp. 228–242. Springer, Heidelberg (2011). doi:10.​1007/​978-3-642-23496-5_​17 CrossRef
7.
Zurück zum Zitat Garasia, S.S., Rana, D.P., Mehta, R.G.: HTTP botnet detection using frequent pattern set mining. Int. J. Eng. Sci. Adv. Technol. 2(3), 619–624 (2012) Garasia, S.S., Rana, D.P., Mehta, R.G.: HTTP botnet detection using frequent pattern set mining. Int. J. Eng. Sci. Adv. Technol. 2(3), 619–624 (2012)
8.
Zurück zum Zitat Haddadi, F., Morgan, J., Filho, E.G., Zincir-Heywood, A.N.: Botnet behaviour analysis using IP Flows with HTTP filters using classifiers. In: 2014 28th International Conference on Advanced Information Networking and Applications Workshops, pp. 7–12 (2014) Haddadi, F., Morgan, J., Filho, E.G., Zincir-Heywood, A.N.: Botnet behaviour analysis using IP Flows with HTTP filters using classifiers. In: 2014 28th International Conference on Advanced Information Networking and Applications Workshops, pp. 7–12 (2014)
9.
Zurück zum Zitat Khillari, A., Augustine, A.: HTTP-based botnet detection technique using Apriori algorithm with actual time duration. Int. J. Comput. Eng. Appl. XI(III), 13–18 (2017) Khillari, A., Augustine, A.: HTTP-based botnet detection technique using Apriori algorithm with actual time duration. Int. J. Comput. Eng. Appl. XI(III), 13–18 (2017)
11.
Zurück zum Zitat Nazario, J., Holz, T.: As the net churns: fast-flux botnet observations. In: 3rd International Conference on Malicious and Unwanted Software, MALWARE 2008. IEEE, 7–8 October 2008. doi:10.1109/MALWARE.2008.4690854 Nazario, J., Holz, T.: As the net churns: fast-flux botnet observations. In: 3rd International Conference on Malicious and Unwanted Software, MALWARE 2008. IEEE, 7–8 October 2008. doi:10.​1109/​MALWARE.​2008.​4690854
13.
Zurück zum Zitat Tyagi, R., Paul, T., Manoj, B.S., Thanudas, B.: A novel HTTP botnet traffic detection method. In: IEEE INDICON (2015) Tyagi, R., Paul, T., Manoj, B.S., Thanudas, B.: A novel HTTP botnet traffic detection method. In: IEEE INDICON (2015)
14.
Zurück zum Zitat Tyagi, A.K., Nayeem, S.: Detecting HTTP botnet using Artificial Immune System (AIS). Int. J. Appl. Inf. Syst. (IJAIS) 2(6) (2012). ISSN: 2249-0868. Foundation of Computer Science FCS, New York, USA Tyagi, A.K., Nayeem, S.: Detecting HTTP botnet using Artificial Immune System (AIS). Int. J. Appl. Inf. Syst. (IJAIS) 2(6) (2012). ISSN: 2249-0868. Foundation of Computer Science FCS, New York, USA
15.
Zurück zum Zitat Kirubavathi Venkatesh, G., Anitha Nadarajan, R.: HTTP botnet detection using adaptive learning rate multilayer feed-forward neural network. In: Askoxylakis, I., Pöhls, H.C., Posegga, J. (eds.) WISTP 2012. LNCS, vol. 7322, pp. 38–48. Springer, Heidelberg (2012). doi:10.1007/978-3-642-30955-7_5 Kirubavathi Venkatesh, G., Anitha Nadarajan, R.: HTTP botnet detection using adaptive learning rate multilayer feed-forward neural network. In: Askoxylakis, I., Pöhls, H.C., Posegga, J. (eds.) WISTP 2012. LNCS, vol. 7322, pp. 38–48. Springer, Heidelberg (2012). doi:10.​1007/​978-3-642-30955-7_​5
16.
Zurück zum Zitat Weimer, F.: Passive DNS replication. In: Proceedings of 1st Conference on Computer Security Incident, Singapore (2005) Weimer, F.: Passive DNS replication. In: Proceedings of 1st Conference on Computer Security Incident, Singapore (2005)
18.
Zurück zum Zitat Zhao, D., Traore, I., Sayed, B., Lu, W., Saad, S., Ghorbani, A., Garant, D.: Botnet detection based on traffic behavior analysis and flow intervals. Elsevier J. Comput. Secur. 39, 2–16 (2013)CrossRef Zhao, D., Traore, I., Sayed, B., Lu, W., Saad, S., Ghorbani, A., Garant, D.: Botnet detection based on traffic behavior analysis and flow intervals. Elsevier J. Comput. Secur. 39, 2–16 (2013)CrossRef
19.
Zurück zum Zitat Zhao, D., Traore, I.: P2P botnet detection through malicious fast flux network identification. In: 7th International Conference on P2P, Parallel, Grid, Cloud, and Internet Computing - 3PGCIC 2012, 12–14 November 2012, Victoria, BC, Canada (2012) Zhao, D., Traore, I.: P2P botnet detection through malicious fast flux network identification. In: 7th International Conference on P2P, Parallel, Grid, Cloud, and Internet Computing - 3PGCIC 2012, 12–14 November 2012, Victoria, BC, Canada (2012)
Metadaten
Titel
Holistic Model for HTTP Botnet Detection Based on DNS Traffic Analysis
verfasst von
Abdelraman Alenazi
Issa Traore
Karim Ganame
Isaac Woungang
Copyright-Jahr
2017
DOI
https://doi.org/10.1007/978-3-319-69155-8_1