Analysis of DNS TXT Record Usage and Consideration of Botnet Communication Detection
Analysis of DNS TXT Record Usage and Consideration of Botnet Communication Detection
复制标题
DNS TXT记录使用分析及僵尸网络通信检测的思考
DOI:
10.1587/transcom.2017itp0009
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
K. Iida
中科院分区:
文献类型:
--
作者:
Hikaru Ichise;Yong Jin;K. Iida
SUMMARY There have been several recent reports that botnet commu-nicationbetweenbot-infectedcomputersandCommandandControlservers (C&Cservers)usingtheDomainNameSystem(DNS)protocolhasbeenusedbymanycyberattackers.Inparticular,botnetcommunicationbased ontheDNSTXTrecordtypehasbeenobservedinseveralkindsofbotnetattack.Unfortunately,theDNSTXTrecordtypehasmanyformsoflegiti-mateusage,suchashostnamedescription.Inthispaper,inordertodetectandblockoutbotnetcommunicationbasedontheDNSTXTrecordtype, we first differentiate between legitimate and suspicious usages of the DNS TXT record type and then analyze real DNS TXT query data obtained from our campus network. We divide DNS queries sent out from an organization into three types—via-resolver, and indirect and direct outbound queries— and analyze the DNS TXT query data separately. We use a 99-day dataset for via-resolver DNS TXT queries and an 87-day dataset for indirect and direct outbound DNS TXT queries. The results of our analysis show that about 30%, 8% and 19% of DNS TXT queries in via-resolver, indirect and direct outbound queries, respectively, could be identified as suspicious DNS traffic. Based on our analysis, we also consider a comprehensive botnet detection system and have designed a prototype system.