EngineeringData ScienceData MiningMalware SampleThreat DetectionEvasion TechniqueAnti-virus TechniqueBotnet DetectionComputer ScienceDistinct GroupingsInfected MachinesMalware Analysis
In this paper we focus on detecting and clustering distinct groupings of domain names that are queried by numerous sets of infected machines. We propose to analyze domain name system (DNS) traffic, such as Non-Existent Domain (NXDomain) queries, at several premier Top Level Domain (TLD) authoritative name servers to identify strongly connected cliques of malware related domains. We illustrate typical malware DNS lookup patterns when observed on a global scale and utilize this insight to engineer a system capable of detecting and accurately clustering malware domains to a particular variant or malware family without the need for obtaining a malware sample. Finally, the experimental results of our system will provide a unique perspective on the current state of globally distributed malware, particularly the ones that use DNS.
16
IEEE Software · 2011 · 2K citations
Brett Stone-Gross, Marco Cova, Lorenzo Cavallaro et al. · 2009 · 581 citations
Engineering, Information Security, Information Forensics +17
EXPOSURE : Finding malicious domains using passive DNS analysis
Leyla Bilge · 2011 · 485 citations
From throw-away traffic to bots: detecting the rise of DGA-based malware
Manos Antonakakis, Roberto Perdisci, Yacin Nadji et al. · 2012 · 408 citations
Building a dynamic reputation system for DNS
Manos Antonakakis, Roberto Perdisci, David Dagon et al. · 2010 · 366 citations