Detecting and Analyzing Fast-Flux Service Networks
Tung-Ming Koo, Hung-Chang Chang, ChunCheng Chuang - · INTERNATIONAL JOURNAL ON Advances in Information Sciences and Service Sciences · 2012
With the rapid development of the Internet, network security has become a critical issue. A large number of cybercriminals use the Internet to engage in illegal activities, such as circulating Trojan horses, spreading viruses, executing distributed-denial-of-service attacks (DDoS), carrying out mass spam mailings, and setting up phishing websites. These activities require high availability to obtain illicit proceeds. To conceal their fraudulent operations, cybercriminals have begun utilizing an attack method known as fast-flux service networks (FFSN), which are networks formed by compromised proxies to redirect services and present the malicious content created by cybercriminals. This study developed a system to detect malicious domains using FFSN in domains obtained from the Malware Domain List. We investigated the actual status of FFSN being employed in cybercrime and analyzed the distributions of infected nodes.