Home / News

Researchers Report New Method for Detecting Domain-Fluxing

Researchers at Texas A&M University say they have a new method for finding domain-fluxing botnets, which evade detection by constantly alternating domain names. Dr. Narasimha Reddy, who works in the University's Department of Electrical and Computer Engineering, collaborated with student Sandeep Yadav and Ashwath Reddy, as well as with Supranamaya "Soups" Ranjan with Narus Inc., to develop the new method. It can be used to detect botnets like Conficker, Kraken and Torpig, which use the so-called DNS domain-fluxing…

Read full story: Network World

Related topics: Cybercrime, DNS, Domain Names, Malware, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Seriously doesnt sound like a very workable idea to me Suresh Ramasubramanian  –  Mar 29, 2011 8:46 AM PDT

Lexical analysis of domains to detect randomly created (hence, likely bad) domains is not very workable, and might work for, at the most, a few of the more amateurishly coded botnets.  Or for those botnets whose domain creation algos are already reverse engineered.

This has limited utility in terms of the noise it generates (for example domain names transliterated from chinese, finnish etc, or domain names that are words with vowels removed / with alternate spellings..).  Yes there'll be signal but just using lexical analysis as the sole criterion = lots and lots of noise.

And its not a particularly new concept so I seriously dont know what this team from TAMU has accomplished that's actually newsworthy.

The full paper is at http://www.ee.tamu.edu/~reddy/papers/imc2010-yadav.pdf btw.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Nominum Launches 1st Comprehensive Mobile Security Solution That Protects Both Network and End User

Neustar Names Becky Burr as its Chief Privacy Officer

Frontline and Nominum Deliver Integrated DNS-Based Platform to Enhance Enterprise Security

Nominum Launches Comprehensive Suite of DNS-Based Security Solutions for Russian Service Providers

Call for Nominations to the Public Interest Registry .ORG Advisory Council

Nominum Sets New Record for Network Speed and Efficiency

Recursive DNS Talk: Round Trip Times, Delegations and Performance

Oman Relaunches .om with the Support of ARI Registry Services

Implementing a Cyber-Security Code of Conduct: Real-Life Lessons From Australia (Webinar)

Domains Ending With .JP.NET Now Available to the General Public at Bargain Prices

Minds+Machines Wins Back-End Registry Services Contract For .BASKETBALL

DDoS Attacks: Top 10 Trends and Truths (Video)

.US Celebrates American Small Business, Surprises Unsuspecting Small Business Owner

Architelos Introduces 'Velocity' to Help TLDs Market in Evolving Domain Name Industry

Nominum Chairman and Chief Scientist, Dr. Paul Mockapetris Inducted into the Internet Hall of Fame

Nominum and Nixu Software to Deliver Centralized DNS and DHCP Management Solution

Minds + Machines Will Host New dot Rugby gTLD

DNS on Defense, DNS on Offense

Managing Outbound Spam: A New DNS-based Approach For Stopping Abuse (Webinar)

PIR Launches First-Ever .ORG Television Commercial In India

Hot Topics

Nominum

IPv6

Sponsored by
Nominum
Verisign

Security

Sponsored by
Verisign
Afilias

DNS Security

Sponsored by
Afilias
dotMobi

Mobile

Sponsored by
dotMobi
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines