Domain Algorithmically Generated Botnet Detection and Analysis

Published: 2014, Last Modified: 08 Jan 2026SecureComm (1) 2014EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: To detect domains used by botnet and generated by algorithms, a new technique is proposed to analyze the query difference between algorithmically generated domain and legal domain based on a fact that every domain name in the domain group generated by one botnet has similar live time and query style. We look for suspicious domains in DNS traffic, and use change distance to verify these suspicious domains used by botnet. Then we tried to describe botnet change rate and change scope using domain change distance. Through deploying our system at operators’ RDNS, experiments were carried to validate the effectiveness of detection method. The experiment result shows that the method can detect algorithmically generated domains used by botnet.
Loading