Grouping Domain Names using DNS Query Graph

Je-Hyun Lee, Jonghoon Kwon, Hyo Jeong Shin, Heejo Lee · 2010

Many malwares have the network activities for command and control, update, propagation, and so on. Because of the use of domain names while the network activities, those malicious activities are observed and have been blocked on the DNS. However, to evade static blacklists, recent malwares are using numbers of newly generated domain names. In this paper, we introduce a domain name grouping using DNS query graph containing query strategy of DNS clients. By grouping the domain names which have the statistically and sequentially similar query strategy, we extract the malicious domain names groups of the multi-domain malwares from the numerous numbers of domain names. From the experiments with the DNS trace of an ISP network, we find tens of multi-domain malwares, and commonly observed unique DNS query strategies. As the contribution of method, the grouping result enhances the efficiency of blacklists by detecting newly appeared malicious domain names.

Read the paper · More papers on PaperTik