Genetic-based real-time fast-flux service networks detection

Hui Tang Lin, Ying You Lin, Jui Wei Chiang

研究成果: Article同行評審

21 引文 斯高帕斯(Scopus)


A new DNS technique called Fast-Flux Service Network (FFSN) has been employed by bot herders to hide malicious activities and extend the lifetime of malicious root servers. Although various methods have been proposed for detecting FFSNs, these mechanisms have low detection accuracy and protracted detection time. This study presents a novel detection scheme, designated as the Genetic-based ReAl-time DEtection (GRADE) system, to identify FFSNs in real time. GRADE differentiates between FFSNs and benign services by employing two new characteristics: the entropy of domains of preceding nodes for all A records and the standard deviation of round trip time to all A records. By applying genetic algorithms, GRADE is able to find the best strategy to detect current FFSN trends. Empirical results show GRADE has very high detection accuracy (∼98%) and gives results within a few seconds. It provides considerable improvement over existing reference schemes such Flux-Score [8], SSFD [13], and FFSD [14].

頁(從 - 到)501-513
期刊Computer Networks
出版狀態Published - 2013 2月 4

All Science Journal Classification (ASJC) codes

  • 電腦網路與通信


深入研究「Genetic-based real-time fast-flux service networks detection」主題。共同形成了獨特的指紋。