Botnet detection method based on DNS (Domain Name System) flow characteristics
A botnet and detection method technology, applied in the field of botnet detection based on DNS traffic characteristics, can solve the problems of not representing the real characteristics of traffic, small amount of data, and no network traffic test.
Patent Information
- Authority / Receiving Office
- CN · China
- Current Assignee / Owner
- Publication Date
- 2016-08-24
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention relates to a DNS domain name technology and a machine learning system classification algorithm. In particular, it relates to a botnet detection method based on DNS traffic characteristics. Background technique
[0002] Among the current domain name generation technologies, there are mainly:
[0003] (1) Domain-Flux technology: Domain-Flux refers to the behavior of continuously changing and assigning multiple domain names to one or more IPs.
[0004] (2) Fast-Flux technology: There are two types of this technology: Single-Flux domain name technology and Double-Flux domain name technology.
[0005] The Single-Flux domain name technology can be compared to the Tor network. In the botnet based on the Single-Flux domain name technology, each zombie host is a redirection node, so that the optimal addressing process can be realized based on the redirection of different zombie hosts. , on the one hand to avoid the impact of a single node on th...
Examples
Embodiment Construction
[0055] The botnet detection method based on DNS traffic characteristics of the present invention will be described in detail below in conjunction with the embodiments and the accompanying drawings.
[0056] The botnet detection method based on DNS flow characteristics of the present invention includes a Domain-Flux botnet detection method and a Fast-Flux botnet detection method based on DNS flow characteristics.
[0057] Such as figure 1 Shown, the Domain-Flux botnet detection method based on DNS traffic characteristic of the present invention, comprises the steps:
[0058] 1) Read the domain name, including reading the legal domain name, and extracting the legal main domain name, and reading the illegal domain name generated by the DGA algorithm, and extracting the illegal main domain name, combining the legal main domain name and the illegal main domain name to form a target set;
[0059] 2) Process the obtained target set, extract the length of each domain name after proce...