Efficient detection of malicious nodes based on DNS and statistical methods
Peter Marko, Peter Vilhan · 2012
The power and flexibility of botnets is rising together with increasing the computational power of personal computers and growing network bandwidth. This implies extreme demands on ISP's security resources in contrast to minimizing the delay and maximizing the throughput of the network. The main contribution of our approach is ability to detect botnet's nodes in LAN using resource friendly solution. This brings high efficiency into the dealing with malicious host's activity. The proposed solution can be transparently integrated into existing security infrastructure even on legacy hardware.