Detection of fast flux service networks

  • Authors:
  • Scott Campbell;Stephen Chan;Jason R. Lee

  • Affiliations:
  • Lawrence Berkeley National Laboratory, National Energy Research Scientific Computing Center, Berkeley, CA;Lawrence Berkeley National Laboratory, National Energy Research Scientific Computing Center, Berkeley, CA;Lawrence Berkeley National Laboratory, National Energy Research Scientific Computing Center, Berkeley, CA

  • Venue:
  • AISC '11 Proceedings of the Ninth Australasian Information Security Conference - Volume 116
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Fast Flux Service Networks (FFSN) apply high availability server techniques to the business of malware distribution. FFSNs are similar to commercial content distribution networks (CDN), such as Akamai, in terms of size, scope, and business model, serving as an outsourced content delivery service for clients. Using an analysis of DNS traffic, we derive a sequential hypothesis-testing algorithm based entirely on traffic characteristics and dynamic white listing to provide real time detection of FFSNs in live traffic. We improve on existing work, providing faster and more accurate detection of FFSNs. We also investigate a category of hosts not fully explored in previous detectors - Open Content Distribution Networks (OCDN) that share many of the characteristics of FFSNs.