Botnet Detection Using DNS and HTTP Traffic Analysis

Agung Udiyono, Charles Ci-Wen Lim, Lukas Lukas · 2020

To perform a large scale attack on the victim, cyber attacker usually prepares thousands if not millions of infected computers to accomplish the goal. Once the infected computers, also called botnet, are ready, they will communicate with the Command and Control (C&C) server to obtain the instruction to perform their acts. Botnet tries to disguise their communication as regular traffic by using commonly used protocols such as HTTP so that their conversation with C&C is not blocked by the firewall. This research explores botnet's footprints using both HTTP and DNS protocols and analyzes their behaviors to select the most appropriate features of HTTP and DNS protocols to be used in our classification model. The developed model has been shown to provide 86% accuracy in distinguishing botnet from benign traffic on the enterprise network.

Read the paper · More papers on PaperTik