2015 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks 2015
DOI: 10.1109/dsn.2015.35
|View full text |Cite
|
Sign up to set email alerts
|

Segugio: Efficient Behavior-Based Tracking of Malware-Control Domains in Large ISP Networks

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
54
0

Year Published

2016
2016
2020
2020

Publication Types

Select...
6
2
1

Relationship

1
8

Authors

Journals

citations
Cited by 88 publications
(55 citation statements)
references
References 9 publications
1
54
0
Order By: Relevance
“…SpiderWeb [36] is also a system that is able to detect malicious web pages by crowd-sourcing redirection chains. Segugio [32] tracks new malwarecontrol domain names in very large ISP networks. WebWitness [27] automatically traces back malware download paths to understand attack trends.…”
Section: Related Workmentioning
confidence: 99%
“…SpiderWeb [36] is also a system that is able to detect malicious web pages by crowd-sourcing redirection chains. Segugio [32] tracks new malwarecontrol domain names in very large ISP networks. WebWitness [27] automatically traces back malware download paths to understand attack trends.…”
Section: Related Workmentioning
confidence: 99%
“…More recently, authors in [18] build bipartite graphs from passive DNS traffic collected from large ISP networks, with the goal of representing the who is querying what relationship. They run a graph-based behavioral classifier that suggests for domains used in C&C operations.…”
Section: Related Workmentioning
confidence: 99%
“…1-20) had more contributions and higher GI scores than both rIP features (Nos. [21][22][23][24][25][26][27][28][29][30][31][32][33][34][35][36][37][38] 4.1 did not contain such easy-toanswer domain names. As a result, the importance of these TVP features using Alexa1k and Alexa10k is relatively low.…”
Section: Effectiveness Of Each Featurementioning
confidence: 99%
“…Sato et al [38] used the co-occurrence characteristics of DNS queries to C&C domain names from multiple malware-infected hosts in a network to extend domain name blacklists. Also, Rahbarinia et al [37] proposed Segugio to detect new C&C domain names from DNS query behaviors in large ISP networks. This system requires malware-infected hosts in a network; however, our approach works without malware-infected hosts.…”
Section: User-centric Approachmentioning
confidence: 99%