Show simple item record

dc.contributor.advisorNarasimha Reddy, Annappa Reddy
dc.creatorAshwath Kumar Krishna Reddy
dc.date.accessioned2011-10-21T22:03:16Z
dc.date.accessioned2011-10-22T07:13:08Z
dc.date.available2011-10-21T22:03:16Z
dc.date.available2011-10-22T07:13:08Z
dc.date.created2010-08
dc.date.issued2011-10-21
dc.date.submittedAugust 2010
dc.identifier.urihttps://hdl.handle.net/1969.1/ETD-TAMU-2010-08-8417
dc.description.abstractRecent Botnets such as Conficker, Kraken and Torpig have used DNS based "domain fluxing" for command-and-control, where each Bot queries for existence of a series of domain names and the owner has to register only one such domain name. In this report, we develop a methodology to detect such "domain fluxes" in DNS traffic by looking for patterns inherent to domain names that are generated algorithmically, in contrast to those generated by humans. In particular, we look at distribution of alphanumeric characters as well as bigrams in all domains that are mapped to the same set of IP-addresses. We present and compare the performance of several distance metrics, including KL-distance and Edit distance. We train by using a good data set of domains obtained via a crawl of domains mapped to all IPv4 address space and modeling bad data sets based on behaviors seen so far and expected. We also apply our methodology to packet traces collected at two Tier-1 ISPs and show we can automatically detect domain fluxing as used by Conficker botnet with minimal false positives. We are also able to detect new botnets and other malicious networks using our method.en
dc.format.mimetypeapplication/pdf
dc.language.isoen_US
dc.subjectconfickeren
dc.subjectbotnetsen
dc.subjectdomain fluxingen
dc.titleDetecting Networks Employing Algorithmically Generated Domain Namesen
dc.typeThesisen
thesis.degree.departmentElectrical and Computer Engineeringen
thesis.degree.disciplineComputer Engineeringen
thesis.degree.grantorTexas A&M Universityen
thesis.degree.nameMaster of Scienceen
thesis.degree.levelMastersen
dc.contributor.committeeMemberBettati, Ricardo
dc.contributor.committeeMemberShakkotai, Srinivas
dc.type.genrethesisen
dc.type.materialtexten


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record