CSO - Online criminals have evolved their tactics to harden their botnets against takedown using a variety of tactics, including fast-flux networks and Conficker-like dynamic domain generation. Yet, such tactics can also pinpoint when such networks are being created by bot operators, according to research from the Georgia Institute of Technology.
The research found that dynamically detecting changes in the domain name system (DNS) can lead to the early detection of botnets. When bot masters create the infrastructure for a botnet, the reputation of the domain names can tip off defenders. In two papers, one released last year ( PDF) and one to be published in September, GATech researchers found that they can detect anomalies in the domain name system indicative of botnets and have documented recognition rates greater than 98 percent.
Also see "The botnet hunters"
Monday, network security firm Damballa announced a service based on the research to provide intelligence on botnet-infected systems. Called FirstAlert, the service can detect the characteristic DNS queries indicative of botnet infections inside a customer's network.
"If you can detect the domain abuse early enough in the infection lifecycle, then you can get ahead of the threat," says David Holmes, vice president of marketing for Damballa. "If we see a domain lookup in a customer environment we haven't seen before, we can say, that's interesting."
The two papers describe two systems. One, Notos, dynamically determines the reputation of a domain-name/IP-address pairs. The system collects DNS query data from registrars and analyzes the domain structure, focusing on the network and zone characteristics.
[ Also see: "What a botnet looks like"
]"It builds models of known legitimate domains and malicious domains, and uses these models to compute a reputation score for a new domain indicative of whether the domain is malicious or legitimate," writes Manos Antonakakis, a researcher at GATech and co-author of the paper.
The other, Kopis, can detect changes across the DNS infrastructure of a company, Internet service provider or the global Internet, that is characteristic of malicious networks. The systems require about 5 days of training to begin to detect botnets, Holmes says.
"Kopis is a machine learning technology," he says. "It has been trained or can be trained to understand lookup patterns and periodicity and profiles ... based on the diversity of the lookups."
The systems used together have been able to detect botnets, such as the IMDDOS and those built on SpyEye. Many times, it can detect botnets weeks before they actually go active and start sending out malware, Holmes says.
The technology is not meant to be used as a standalone service, but in conjunction with other expert systems such as spam engines. Notos, for example, will penalize legitimate Web sites that are hosted with a provider that also hosts malicious domain names.
Read more about malware/cybercrime in CSOonline's Malware/Cybercrime section.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Security Hardware and Software White Papers
- Close a Dangerous Vulnerability: Automated Methods for Managing Admin Rights
- In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for...
- Case Study: Kimberly-Clark Implements Workday for Global Human Resources
- See how Kimberly-Clark evaluated and deployed SaaS when it upgraded its human capital management system, gaining software security and peace of mind across...
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Security Hardware and Software Webcasts