|
Domain Name Service as an IDS |
|
|
|
Source: Cees de Laat, Karst Koymans - Posted by Eric Lubow
|
How DNS can be used for detecting and monitoring badware in a network.
Since bots started using domain names for connection with their controller, tracking and removing them has become a hard task. This research is a first glance at the usability of DNS traffic and logs for detection of this malicious network activity. Detection of bots is possible by DNS information gathered from the network by placing counters and triggers on specific events in the data analysis.
Read this full article at Cees de Laat, Karst Koymans
Powered by AkoComment! |