Botnets Detection in DNS logs using machine learning
Félix Óscar Fernández Peña, Adrian Zurita-Amores · 2019
Botnets detection is a computationally expensive problem for which there is no deterministic solution yet. The scientific problem that raises is how to define a procedure for botnet detection with limited resources. In this paper, a botnets' detection method, based on machine learning, is formalized and evaluated. This proposal makes use of Splunk, a tool that allowed us to use the Random Forest algorithm to analyze DNS logs in order to detect connections to C&C servers. The resulting procedure complements the use of machine learning with the verification against other data sources for improving the results. The achieved results showed an error margin of +/- 5.44 for 18,748,713 events which were analyzed. This way, the validity of this proposal was proved.