A review of botnet detection approaches based on DNS traffic analysis

3Citations
Citations of this article
18Readers
Mendeley users who have this article in their library.
Get full text

Abstract

A botnet is a network of computing devices being commanded by an attacker, a daily Internet problem, causing extensive economic damage for organizations and individuals. With the avail of botnets, attackers can perform remote control on exploited machines, performing several malicious activities, since it enormously increases a botnet’s survivability by evading detection, Domain Name System (DNS) nowadays is a favourable botnet communication channel. Fortunately, many strategies have been introduced and developed to undertake the issue of botnets based on DNS resolving; this review explores the various botnet detection techniques through providing a study for detection approached based on DNS traffic analysis. Some related topics, including technological background, life cycle, evasion, and detection techniques of botnets are introduced.

Author supplied keywords

Cite

CITATION STYLE

APA

Al-Mashhadi, S., Anbar, M., Karuppayah, S., & Al-Ani, A. K. (2019). A review of botnet detection approaches based on DNS traffic analysis. In Lecture Notes in Networks and Systems (Vol. 67, pp. 305–321). Springer. https://doi.org/10.1007/978-981-13-6031-2_21

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free