Abstract
Botnets that use DNS technology are a serious threat on the Internet today. The potential of botnets is very large, from the spread of malware, ransomware, spam mailings to the theft of confidential information and money from bank accounts. Analysis of known methods and means of identification of botnets that use DNS has demonstrated the insufficient level of detection capacity of this type of botnets. Therefore, it is necessary to improve the method of botnets detection. The paper presents botnet detection approach based on DNS. The paper proposes a method of identifying botnets that use DNS based on the Decision Tree classifier with the application of the AdaBoost algorithm. The method allows you to ensure the detection of botnets that use DNS based on the characteristics of this technology of malicious software. The Decision Tree application algorithm is argued by the fact that it is a powerful tool for classification and prediction, and to strengthen the work of the above classifier, the AdaBoost algorithm was used in the study.
| Original language | English |
|---|---|
| Pages (from-to) | 400-410 |
| Number of pages | 11 |
| Journal | CEUR Workshop Proceedings |
| Volume | 3156 |
| Publication status | Published - 2022 |
| Event | 3rd International Workshop on Intelligent Information Technologies and Systems of Information Security, IntelITSIS 2022 - Khmelnytskyi, Ukraine Duration: 23 Mar 2022 → 25 Mar 2022 |
Keywords
- AdaBoost
- Botnet
- Botnet Detection
- Computer Network
- Computer system
- Cyberattack
- Cybersecurity
- DNS
- Decision Tree
- Malicious traffic
- Malware
ASJC Scopus subject areas
- General Computer Science
Fingerprint
Dive into the research topics of 'Botnet Detection Approach Based on DNS'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver