A study on detection and blocking of DNS-based botnet communication
光 一瀨 · Institutional Repositories DataBase (IRDB) · 2020
In recent years, though the next-generation Internet provides higher QoS and various new capabilities, the number of high-impact security incidents is increasing.Some of these security incidents use malicious programs called bots, which have become a serious problem.A bot is a malicious program, which is spreading by e-mail attachments, Web sites, USB memories, etc.The bot performs various attacks such as DDoS attacks and sending spam mails.The bot-infected PC receives various attack commands from a server called the Command and Control (C&C) server, and attacks the others PCs according to the commands.Botnet communication is a logical network between a C&C server and bot-infected PCs.It is important for network administrators to detect and to remove botinfected PCs in their organizations.In this thesis, I focus on botnet communication using DNS queries, which is a typical communication protocol used by various latest botnets, and discuss a system that automatically detects and blocks it.The thesis includes five chapters.Chapter 1 gives the background, objective and overview of the proposed solutions in this thesis.First, I present the threats of botnet communications, and the issues of those studies, and discusses the purpose of this study.Existing researches on botnet communication have not analyzed (1) legitimate usage and unconfirmed usage of DNS TXT records, and (2) DNS traffic without using official DNS full resolver for the use of direct outbound DNS queries in botnet communication.Moreover, (3) most researchers have not been realized automatic detection and blocking of botnet communication of direct outbound DNS queries.Chapter 2 introduces the details of the botnet, the DNS protocol, and the behavior of the botnet using DNS.I also introduce existing researches, and the issues to be solved.In chapter 3, I discuss solutions of issues (1) and (2).In order to solve issues (1) i and (2), I first differentiate between legitimate and suspicious usages of the DNS query and then analyze real DNS query data obtained from a campus network.I discover and divide DNS queries sent out from an organization into three types -via-resolver, and indirect and direct outbound queries -and analyze the DNS query data separately.I use a 99-day dataset for via-resolver DNS TXT queries and an 87-day dataset for indirect and direct outbound queries.The results of my analysis show that about 30%, 8% and 19% of DNS queries in via-resolver, indirect and direct outbound queries, respectively, could be identified as suspicious DNS traffic.Based on my analysis, I also consider a comprehensive botnet detection system and have designed a prototype system.In chapter 4, I study the problem (3).Namely, I design and implement the system to detect and block the botnet communication using direct outbound DNS query as an advancement from the botnet detection system roughly proposed in chapter 3. I design and implement the system to detect and block the botnet communication using direct outbound DNS query.In the proposed mechanism, all DNS traffic of an organization will be captured and analyzed in order to extract all NS records which will be stored in a white list database.Then all the outgoing DNS queries will be checked and those destined to the IP addresses that are not included in the white list will be blocked as DNS-based botnet communication.I have implemented a prototype system and evaluated the functionality in an SDN-based experimental network.The results showed that the prototype system worked well as I expected and accordingly I consider that the proposed mechanism is capable of detecting and blocking some specific types of DNS-based botnet communication.Chapter 5 summarizes the results of this research and presents the future research directions which should be future issues.Writing this thesis, I have received a great deal of assistance, support, and guidance from people around me.I would like to sincerely thank them all for supporting me everything throughout Doctoral course.I would first like to