作者
Matthew Thomas, Aziz Mohaisen
发表日期
2014
研讨会论文
WWW
简介
In this paper we focus on detecting and clustering distinct groupings of domain names that are queried by numerous sets of infected machines. We propose to analyze domain name system (DNS) traffic, such as Non-Existent Domain (NXDomain) queries, at several premier Top Level Domain (TLD) authoritative name servers to identify strongly connected cliques of malware related domains. We illustrate typical malware DNS lookup patterns when observed on a global scale and utilize this insight to engineer a system capable of detecting and accurately clustering malware domains to a particular variant or malware family without the need for obtaining a malware sample. Finally, the experimental results of our system will provide a unique perspective on the current state of globally distributed malware, particularly the ones that use DNS.
引用总数
2014201520162017201820192020202120222023202445142119121010731
学术搜索中的文章
M Thomas, A Mohaisen - Proceedings of the 23rd International Conference on …, 2014