How non-existent domain names can unveil DGA botnets
ID: f126eb6c-8276-580c-b621-3c2683cf0c9f
STIX ID: report--f126eb6c-8276-580c-b621-3c2683cf0c9f
Feed Name: CERT Polska
This report outlines how NXDomain responses can be leveraged to detect DGA-based botnets, detailing methods such as sequential hypothesis testing for host reputation, DNS failure graphs for co-clustering, prefiltering and clustering of hosts by NXDomain similarity, and augmenting with lexical and behavioral features. It highlights the need for whitelisting and careful tuning to reduce false positives from benign applications and acknowledges potential evasion strategies by botnets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
