2013
DOI: 10.1007/978-3-642-37192-9_53
|View full text |Cite
|
Sign up to set email alerts
|

Malicious Automatically Generated Domain Name Detection Using Stateful-SBB

Abstract: Abstract. This work investigates the detection of Botnet Command and Control (C&C) activity by monitoring Domain Name System (DNS) traffic. Detection signatures are automatically generated using evolutionary computation technique based on Stateful-SBB. The evaluation performed shows that the proposed system can work on raw variable length domain name strings with very high accuracy.

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1

Citation Types

0
4
0

Year Published

2015
2015
2019
2019

Publication Types

Select...
3
2
1

Relationship

1
5

Authors

Journals

citations
Cited by 9 publications
(4 citation statements)
references
References 8 publications
0
4
0
Order By: Relevance
“…Some of the works in the literature proposed specific packet analysis methods to detect botnet behaviour . These systems have focussed on specific packets and features from the header and/or payload sections of these packets to identify the type of malware they are interested in.…”
Section: Methodsmentioning
confidence: 99%
See 2 more Smart Citations
“…Some of the works in the literature proposed specific packet analysis methods to detect botnet behaviour . These systems have focussed on specific packets and features from the header and/or payload sections of these packets to identify the type of malware they are interested in.…”
Section: Methodsmentioning
confidence: 99%
“…These systems have focussed on specific packets and features from the header and/or payload sections of these packets to identify the type of malware they are interested in. For example, Haddadi et al extracted the domain name from the DNS packets to detect automatically generated malicious domain names while Mohaisen et al introduced a set of features focussing on the Zeus botnet. The features introduced by Mohaisen et al based on a priori knowledge are used in the evaluations of the proposed packet payload–based system.…”
Section: Methodsmentioning
confidence: 99%
See 1 more Smart Citation
“…Haddadi et. al.,[4] suggest an evolutionary computation technique based on Stateful-SBB to detect malicious botnet. Shi et.…”
mentioning
confidence: 99%