Publication | Closed Access
Revealing botnet membership using DNSBL counter-intelligence
206
Citations
10
References
2006
Year
Unknown Venue
Botnets, networks of compromised machines, are commonly used for spam, click fraud, and denial‑of‑service attacks, and identifying their members is difficult without disrupting operations. The study investigates how monitoring DNS‑based blackhole list (DNSBL) lookups can reveal botnet membership, examining the prevalence of DNSBL reconnaissance over a 45‑day period and exploring counter‑intelligence methods to identify likely bots. By applying heuristics to DNSBL queries that indicate botmaster reconnaissance, the authors compile a list of probable bots from a mirror of a well‑known blacklist. The analysis shows that bots conduct reconnaissance on behalf of other bots, and the authors propose counter‑intelligence techniques that could enable early bot detection.
Botnets--networks of (typically compromised) machines--are often used for nefarious activities (e.g., spam, click fraud, denial-of-service attacks, etc.). Identifying members of botnets could help stem these attacks, but passively detecting botnet membership (i.e., without disrupting the operation of the botnet) proves to be difficult. This paper studies the effectiveness of monitoring lookups to a DNS-based blackhole list (DNSBL) to expose botnet membership. Using heuristics to identify which DNSBL lookups are perpetrated by a botmaster performing such reconnaissance, we are able to compile a list of likely bots. This paper studies the prevalence of DNSBL reconnaissance observed at a mirror of a well-known blacklist for a 45- day period, identifies the means by which botmasters are performing reconnaissance, and suggests the possibility of using counter-intelligence to discover likely bots. We find that bots are performing reconnaissance on behalf of other bots. Based on this finding, we suggest counterintelligence techniques that may be useful for early bot detection.
| Year | Citations | |
|---|---|---|
Page 1
Page 1