Skip to main navigation Skip to search Skip to main content

Detecting malicious fast flux domains

  • Mahmoud T. Qassrawi*
  • , Hongli Zhang
  • *Corresponding author for this work
  • School of Computer Science and Technology, Harbin Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Fast-flux service networks (FFSN) are new emerging phenomenon in the internet. Fast-flux networks use proxy networks of compromised machines to redirect and host scam service to achieve high availability. Such technique helps scam websites to avoid being traced and taken down by security professionals. In this paper, we use alternative decision tree algorithm to identify presence of fast-flux domains by analyzing only one address record (A-record) of DNS lookup, which achieves fast detection.

Original languageEnglish
Title of host publicationMechatronics and Applied Mechanics
Pages1264-1273
Number of pages10
DOIs
StatePublished - 2012
Externally publishedYes
EventMechatronics and Applied Mechanics - Hong Kong, Hong Kong
Duration: 27 Dec 201128 Dec 2011

Publication series

NameApplied Mechanics and Materials
Volume157-158
ISSN (Print)1660-9336
ISSN (Electronic)1662-7482

Conference

ConferenceMechatronics and Applied Mechanics
Country/TerritoryHong Kong
CityHong Kong
Period27/12/1128/12/11

Keywords

  • A record
  • Availability
  • DNS lookup
  • Fast flux

Fingerprint

Dive into the research topics of 'Detecting malicious fast flux domains'. Together they form a unique fingerprint.

Cite this