CMDHunter: Finding malicious domains from cyclical communication

Zhen yong Xie, Liming Wang, Ma Yuanyuan, Jing Yang, Zhen Xu · 2016

Malwares always query DNS names to locate their C&C servers and keep regular communication with them, either for fetching instructions or checking updates. Traditional works consider such regular communication as a single-cycle behavior. However we find that many malwares communicate with their C&C servers in a multi-cycle way, which makes them more like normal and evading existing defense mechanisms. In this paper, we present a novel system, named CMDHunter, to find malicious domains involved in cyclical communication from passive DNS data. We first define the cyclical behavior in a formal way, and propose an improved histogram-based algorithm to identify it. To determine the domains which are malicious or not, we build a classifier with characterizing a DNS name according to its queried requests, resolved IP, search results in a search engine and register information. We evaluate CMDHunter with an almost three-week, real-word DNS data set from a local institute /16 network. The results show that our approach can detect unknown malicious domains in cyclical communication effectively.

Read the paper · More papers on PaperTik