A botnet is a network of computing devices being commanded by an attacker, a daily Internet problem, causing extensive economic damage for organizations and individuals. With the avail of botnets, attackers can perform remote control on exploited machines, performing several malicious activities, since it enormously increases a botnet’s survivability by evading detection, Domain Name System (DNS) nowadays is a favourable botnet communication channel. Fortunately, many strategies have been introduced and developed to undertake the issue of botnets based on DNS resolving; this review explores the various botnet detection techniques through providing a study for detection approached based on DNS traffic analysis. Some related topics, including technological background, life cycle, evasion, and detection techniques of botnets are introduced.
CITATION STYLE
Al-Mashhadi, S., Anbar, M., Karuppayah, S., & Al-Ani, A. K. (2019). A review of botnet detection approaches based on DNS traffic analysis. In Lecture Notes in Networks and Systems (Vol. 67, pp. 305–321). Springer. https://doi.org/10.1007/978-981-13-6031-2_21
Mendeley helps you to discover research relevant for your work.