Phoenix: DGA-Based Botnet Tracking and Intelligence

Phoenix: DGA-Based Botnet Tracking and Intelligence
复制标题

DOI:
10.1007/978-3-319-08509-8_11
复制
发表时间:
2014-07
期刊:
--
影响因子:
--
通讯作者:
S. Schiavoni;F. Maggi;L. Cavallaro;S. Zanero
S. Schiavoni;F. Maggi;L. Cavallaro;S. Zanero
中科院分区:
其他
文献类型:
--
作者:
S. Schiavoni;F. Maggi;L. Cavallaro;S. Zanero

文献摘要

被引文献

相似文献

现代僵尸网络依赖于域生成算法(DGAs)来构建弹性命令和控制基础设施。鉴于这种机制的流行,最近的工作集中在分析DNS流量,以识别僵尸网络的基础上,他们的DGA。虽然以前的工作主要集中在侦查上,但我们的重点是支持情报行动。我们proposePhoenix,一种机制,除了告诉DGA和非DGA生成的域除了使用字符串和基于IP的功能的组合,其特征在于背后的DGA,最重要的是,发现组的DGA生成的域是代表各自的僵尸网络。因此,Phoenix可以将以前未知的DGA生成的域与这些组相关联,并生成有关每个跟踪僵尸网络的演变行为的新知识。我们评估了Phoenixon 1,153,516个域,包括来自现代知名僵尸网络的DGA生成的域:在没有监督的情况下,它在94.8%的情况下正确区分了DGA与非DGA生成的域,表征了属于不同DGA的域家族,并帮助“现场”研究人员收集可疑域的情报,以识别正确的僵尸网络。
Modern botnets rely on domain-generation algorithms (DGAs) to build resilient command-and-control infrastructures. Given the prevalence of this mechanism, recent work has focused on the analysis of DNS traffic to recognize botnets based on their DGAs. While previous work has concentrated on detection, we focus on supporting intelligence operations. We proposePhoenix, a mechanism that, in addition to telling DGA- and non-DGA-generated domains apart using a combination of string and IP-based features, characterizes the DGAs behind them, and, most importantly, finds groups of DGA-generated domains that are representative of the respective botnets. As a result,Phoenixcan associate previously unknown DGA-generated domains to these groups, and produce novel knowledge about the evolving behavior of each tracked botnet. We evaluatedPhoenixon 1,153,516 domains, including DGA-generated domains from modern, well-known botnets: without supervision, it correctly distinguished DGA- vs. non-DGA-generated domains in 94.8 percent of the cases, characterized families of domains that belonged to distinct DGAs, and helped researchers “on the field” in gathering intelligence on suspicious domains to identify the correct botnet.