Pretražite po imenu i prezimenu autora, mentora, urednika, prevoditelja

Napredna pretraga

Pregled bibliografske jedinice broj: 874912

Fast-flux Botnet Detection Based on Traffic Response and Search Engines Creditworthiness


Cafuta, Davor; Sruk, Vlado; Dodig, Ivica
Fast-flux Botnet Detection Based on Traffic Response and Search Engines Creditworthiness // Tehnički vjesnik : znanstveno-stručni časopis tehničkih fakulteta Sveučilišta u Osijeku, 25 (2018), 2; 390-400 doi:10.17559/TV-20161012115204 (međunarodna recenzija, članak, znanstveni)


CROSBI ID: 874912 Za ispravke kontaktirajte CROSBI podršku putem web obrasca

Naslov
Fast-flux Botnet Detection Based on Traffic Response and Search Engines Creditworthiness

Autori
Cafuta, Davor ; Sruk, Vlado ; Dodig, Ivica

Izvornik
Tehnički vjesnik : znanstveno-stručni časopis tehničkih fakulteta Sveučilišta u Osijeku (1330-3651) 25 (2018), 2; 390-400

Vrsta, podvrsta i kategorija rada
Radovi u časopisima, članak, znanstveni

Ključne riječi
Botnet ; IDS ; fast-flux

Sažetak
Botnets are considered as the primary threats on the Internet and there have been many research efforts to detect and mitigate them. Today, Botnet uses a DNS technique fast-flux to hide malware sites behind a constantly changing network of compromised hosts. This technique is similar to trustworthy Round Robin DNS technique and Content Delivery Network (CDN). In order to distinguish the normal network traffic from Botnets different techniques are developed with more or less success. The aim of this paper is to improve Botnet detection using an Intrusion Detection System (IDS) or router. A novel classification method for online Botnet detection based on DNS traffic features that distinguish Botnet from a CDN based traffic is presented. Botnet features are classified according to the possibility of usage and implementation in a embedded system. Traffic response is analysed as a strong candidate for online detection. Its disadvantage lies in specific areas where CDN acts as a Botnet. A new feature based on search engine hits is proposed to improve the false positive detection. The experimental evaluations show that proposed classification could significantly improve Botnet detection. A procedure is suggested to implement such a system as a part of an IDS.

Izvorni jezik
Engleski

Znanstvena područja
Računarstvo



POVEZANOST RADA


Ustanove:
Fakultet elektrotehnike i računarstva, Zagreb,
Tehničko veleučilište u Zagrebu

Profili:

Avatar Url Vlado Sruk (autor)

Avatar Url Ivica Dodig (autor)

Avatar Url Davor Cafuta (autor)

Poveznice na cjeloviti tekst rada:

doi hrcak.srce.hr

Citiraj ovu publikaciju:

Cafuta, Davor; Sruk, Vlado; Dodig, Ivica
Fast-flux Botnet Detection Based on Traffic Response and Search Engines Creditworthiness // Tehnički vjesnik : znanstveno-stručni časopis tehničkih fakulteta Sveučilišta u Osijeku, 25 (2018), 2; 390-400 doi:10.17559/TV-20161012115204 (međunarodna recenzija, članak, znanstveni)
Cafuta, D., Sruk, V. & Dodig, I. (2018) Fast-flux Botnet Detection Based on Traffic Response and Search Engines Creditworthiness. Tehnički vjesnik : znanstveno-stručni časopis tehničkih fakulteta Sveučilišta u Osijeku, 25 (2), 390-400 doi:10.17559/TV-20161012115204.
@article{article, author = {Cafuta, Davor and Sruk, Vlado and Dodig, Ivica}, year = {2018}, pages = {390-400}, DOI = {10.17559/TV-20161012115204}, keywords = {Botnet, IDS, fast-flux}, journal = {Tehni\v{c}ki vjesnik : znanstveno-stru\v{c}ni \v{c}asopis tehni\v{c}kih fakulteta Sveu\v{c}ili\v{s}ta u Osijeku}, doi = {10.17559/TV-20161012115204}, volume = {25}, number = {2}, issn = {1330-3651}, title = {Fast-flux Botnet Detection Based on Traffic Response and Search Engines Creditworthiness}, keyword = {Botnet, IDS, fast-flux} }
@article{article, author = {Cafuta, Davor and Sruk, Vlado and Dodig, Ivica}, year = {2018}, pages = {390-400}, DOI = {10.17559/TV-20161012115204}, keywords = {Botnet, IDS, fast-flux}, journal = {Tehni\v{c}ki vjesnik : znanstveno-stru\v{c}ni \v{c}asopis tehni\v{c}kih fakulteta Sveu\v{c}ili\v{s}ta u Osijeku}, doi = {10.17559/TV-20161012115204}, volume = {25}, number = {2}, issn = {1330-3651}, title = {Fast-flux Botnet Detection Based on Traffic Response and Search Engines Creditworthiness}, keyword = {Botnet, IDS, fast-flux} }

Časopis indeksira:


  • Web of Science Core Collection (WoSCC)
    • Science Citation Index Expanded (SCI-EXP)
    • SCI-EXP, SSCI i/ili A&HCI
  • Scopus


Citati:





    Contrast
    Increase Font
    Decrease Font
    Dyslexic Font