Design of Detecting Botnet Communication by Monitoring Direct Outbound DNS Queries

Design of Detecting Botnet Communication by Monitoring Direct Outbound DNS Queries
复制标题

通过监控直接出站 DNS 查询来检测僵尸网络通信的设计

DOI:
10.1109/cscloud.2015.53
复制
发表时间:
2015
期刊:
2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing
影响因子:
--
通讯作者:
K. Iida
K. Iida
中科院分区:
--
文献类型:
--
作者:
Yong Jin;Hikaru Ichise;K. Iida

文献摘要

被引文献

相似文献

域名系统是互联网中使用最广泛的域名解析协议。域名解析对于大多数互联网服务都是必需的,通常由 DNS 完整解析器提供。不幸的是,许多报告表明 DNS 协议最近也被用于僵尸网络通信。受僵尸网络感染的计算机与命令与控制 (C&C) 服务器之间的僵尸网络通信在僵尸网络攻击中是不可或缺的,并且所涉及的 DNS 流量可能不使用 DNS 完整解析器。更重要的是,由于 DNS 协议的普及,很难简单地阻止来自内部计算机的 DNS 流量。一些相关的工作已经启动,但它们只关注 DNS 完整解析器。在本文中,我们重点监控直接出站 DNS 查询,并通过收集权威 NS(名称服务器)记录及其 IP 地址提出了一种新的僵尸网络通信检测方法。我们对我们大学的所有 DNS 流量进行了大约三个月的监控,并在第三方安全站点中检查了直接出站 DNS 查询的目标 IP 地址,以确认所提出方法的有效性。结果证实,平均每天有大约 19% 的 IP 地址被点击,这表明我们提出的方法是有效的,并且在实际操作中进行详细调查时,命中率是可以接受的。
Domain Name System is the most widely used protocol for domain name resolution in the Internet. Domain name resolution is necessary for most of Internet services and it is usually provided by DNS full resolvers. Unfortunately, many reports indicated that DNS protocol was also used in botnet communication recently. Botnet communications between bot-infected computers and Command and Control (C&C) servers are indispensable in botnet attacks and the involved DNS traffic may not use DNS full resolvers. More importantly, due to the popularity of DNS protocol it is difficult to simply block the DNS traffic from internal computers. Several related works have been launched but they only focus on DNS full resolvers. In this paper, we focus on monitoring direct outbound DNS queries and propose a new botnet communication detection method by collecting authoritative NS (Name Server) record and its IP address. We monitored all DNS traffic for about three months in our university and checked the destination IP addresses of direct outbound DNS queries in a third party security site to confirm the effectiveness of the proposed method. The results confirmed that about 19% IP addresses in average have hits per day which indicates that our proposed method is effective and the hit rate is acceptable for detailed investigation in real operation.