Skip to main navigation Skip to search Skip to main content

Botnet Detection Approach Based on DNS

  • Sergii Lysenko
  • , Kira Bobrovnikova
  • , Bohdan Savenko
  • , Piotr Gaj
  • , Oleg Savenko
  • Khmelnytsky National University

Research output: Contribution to journalConference articlepeer-review

4 Citations (Scopus)

Abstract

Botnets that use DNS technology are a serious threat on the Internet today. The potential of botnets is very large, from the spread of malware, ransomware, spam mailings to the theft of confidential information and money from bank accounts. Analysis of known methods and means of identification of botnets that use DNS has demonstrated the insufficient level of detection capacity of this type of botnets. Therefore, it is necessary to improve the method of botnets detection. The paper presents botnet detection approach based on DNS. The paper proposes a method of identifying botnets that use DNS based on the Decision Tree classifier with the application of the AdaBoost algorithm. The method allows you to ensure the detection of botnets that use DNS based on the characteristics of this technology of malicious software. The Decision Tree application algorithm is argued by the fact that it is a powerful tool for classification and prediction, and to strengthen the work of the above classifier, the AdaBoost algorithm was used in the study.

Original languageEnglish
Pages (from-to)400-410
Number of pages11
JournalCEUR Workshop Proceedings
Volume3156
Publication statusPublished - 2022
Event3rd International Workshop on Intelligent Information Technologies and Systems of Information Security, IntelITSIS 2022 - Khmelnytskyi, Ukraine
Duration: 23 Mar 202225 Mar 2022

Keywords

  • AdaBoost
  • Botnet
  • Botnet Detection
  • Computer Network
  • Computer system
  • Cyberattack
  • Cybersecurity
  • DNS
  • Decision Tree
  • Malicious traffic
  • Malware

ASJC Scopus subject areas

  • General Computer Science

Fingerprint

Dive into the research topics of 'Botnet Detection Approach Based on DNS'. Together they form a unique fingerprint.

Cite this