BotScoop: Scalable Detection of DGA Based Botnets Using DNS Traffic

Gulbadan Khehra, Sanjeev Sofat · 2018

Most of the new generation botnets relies on DGA's (Domain Generation Algorithm) to construct a resilient C & C infrastructure for various botnet crime activities. The prevailing use of DGA algorithms has enormously strengthens the capability of botnet's to easily evade detection. Given the prevalence of this whole mechanism, researchers have focused on the DNS traffic analysis in order to recognize the DGA based botnets. In this paper, we present BotScoop, a novel system to detect DGA based botnets by utilizing the DNS traffic only and detecting the command and control server domain with its corresponding IP address. This system has achieved an accuracy of 98.7% for five botnet families such as Ramnit, Cryptolocker, Zeus, Rbot and Conficker. Moreover, this paper also includes evaluation of Recurrent Neural Network(RNN) and Convolution Neural Network(CNN) over detection of DGA domains which concludes that Convolution Neural Network with Long Short Term Network(CNN-LSTM) gives best detection accuracy i.e 99.79%.

Read the paper · More papers on PaperTik