DNS Log Analysis for C&C Botnet Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing botnet detection technologies are ineffective in capturing attack behaviors and locating botnets in a timely manner, particularly due to difficulties in resolving malicious domain names generated by command-and-control servers, which hinders accurate lockdown and suppression of botnet activities across the internet.
Innovation Solution
A C&C domain name analysis-based method that involves acquiring DNS logs, detecting and categorizing C&C domain names using a pre-built domain name analyzer, and determining botnet activity trends through Poisson parameter analysis to facilitate effective suppression measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network traffic analysis is performed based on IRC protocol to detect bot behavior, then some bots can be found, but most malicious domain names generated by C&C servers cannot be resolved, preventing accurate botnet detection and location
Solution Approach 1:
The patent introduces DNS log analysis as an intermediary mechanism to detect botnet activities. Instead of relying on direct network traffic analysis that fails to resolve malicious domains, the system uses DNS logs as a mediator to capture domain name requests and responses, enabling detection of C&C servers even when domain resolution fails at the network level
Solution Approach 2:
The patent replaces the mechanical network traffic analysis approach with a computational domain name analysis system. By substituting traditional network-level detection with domain name pattern recognition and classification algorithms, the system can identify malicious domains without requiring successful resolution, thereby overcoming the limitation of network traffic analysis
2Reliability
If IDS monitors network operation status to detect attack activities, then infected hosts can be locked down, but the system is suitable only for LAN and cannot detect botnets across the whole Internet
Solution Approach 1:
The patent makes the detection system universal by enabling it to function both within LAN environments and across the entire Internet. The domain name analysis approach can be deployed at multiple levels (local DNS servers, centralized logging systems) and works for both internal and external botnet communications, providing multi-functional detection capability
Solution Approach 2:
The patent shifts the detection dimension from network layer monitoring to domain name space analysis. Instead of monitoring network traffic which is limited to LAN scope, the system analyzes domain name requests and responses that can be captured across the entire Internet, expanding the detection scope from local to global
3Loss of information
If honeypot technology is deployed to induce attacks and track attacker behavior, then attack implementation and social network can be analyzed, but a lot of deployment is required and it can be easily controlled as springboard for attack
Solution Approach 1:
The patent extracts the essential detection function from complex honeypot systems. Instead of deploying comprehensive honeypot infrastructure to induce and analyze attacks, the system extracts and analyzes domain name information from DNS logs, providing attacker social network analysis without requiring complex deployment
Solution Approach 2:
The patent converts the harmful effect of botnet domain name generation into a beneficial detection signal. Instead of trying to prevent or induce attacks, the system uses the domain name requests and responses generated by botnets as useful information for detection and analysis, turning the attacker's own communications into detection evidence
Data Source
AI summary
The invention provides a command-and-control (C&C) domain name analysis-based botnet detection method, device, apparatus and medium. The method includes an information acquisition step where DNS logs are acquired; a domain name analysis step where C&C domain names in the DNS logs are detected and the category of each C&C domain name is determined according to a pre-built domain name analyzer; a botnet determination step where whether a botnet exists is determined according to the C&C domain name and the category of C&C domain name. In the C&C domain name analysis-based botnet detection method, device, apparatus and medium provided by the present invention, by analyzing the domain name system (DNS) logs, the C&C domain name used in the attack activity is extracted for further analysis of the types of parasitic Trojans to thereby lock down the bot that the C&C server has controlled. In addition, the botnet activity trend can be analyzed by analyzing the Poisson parameter of each type of the C&C domain name, so as to form effective suppression measures in time.


