Mentor: Positive DNS Reputation to Skim-Off Benign Domains in Botnet C&C Blacklists

Mentor: Positive DNS Reputation to Skim-Off Benign Domains in Botnet C&C Blacklists
复制标题

导师:积极的 DNS 声誉有助于窃取僵尸网络 C 中的良性域

DOI:
10.1007/978-3-642-55415-5_1
复制
发表时间:
2014
期刊:
Comput. Networks
影响因子:
--
通讯作者:
Nicolas Deschamps
Nicolas Deschamps
中科院分区:
--
文献类型:
--
作者:
Nizar Kheir;F. Tran;Pierrette Caron;Nicolas Deschamps

文献摘要

被引文献

相似文献

域名系统(DNS)是互联网上必不可少的基础设施服务。它提供了易于记忆的域名和数字IP地址之间的全球映射。如今,合法用户和恶意应用程序使用这项服务来定位互联网上的内容。然而,僵尸网络越来越依赖DNS连接到它们的命令和控制服务器。在企业网络中检测僵尸感染的一种广泛方法是使用域CC检查DNS流量,而当前的黑名单生成算法通常会添加无害域,从而在检测期间导致大量误报。
The Domain Name System (DNS) is an essential infrastructure service on the internet. It provides a worldwide mapping between easily memorizable domain names and numerical IP addresses. Today, legitimate users and malicious applications use this service to locate content on the internet. Yet botnets increasingly rely on DNS to connect to their command and control servers. A widespread approach to detect bot infections inside corporate networks is to inspect DNS traffic using domain CC and current blacklist generation algorithms often add innocuous domains that lead to a large number of false positives during detection.