Volume 12 Number 4 (Jul. 2017)
Home > Archive > 2017 > Volume 12 Number 4 (Jul. 2017) >
JCP 2017 Vol.12(4): 371-379 ISSN: 1796-203X
doi: 10.17706/jcp.12.4.371-379

Exploring Global IP-Usage Patterns in Fast-Flux Service Networks

Ci-Bin Jiang, Jung-Shian Li
Department of Electrical Engineering, Institute of Computer and Communication Engineering, National Cheng Kung University, Tainan City 701, Taiwan.
Abstract—In recent years, hackers have increasingly used fast-flux techniques to extend the lifetime of malware networks in order to conduct various Advanced Persistent Threat (APT) activities. Such activities typically target nations and or organizations for business or political motives and have the potential to cause immense disruption. Thus, it is essential to study the fast-flux service network and find possible attack behaviors. The literature contains various proposals for FFSN detection. However, these methods are either out of date in terms of the features they use for detection purposes or are unworkable under a new FFSN architecture identified in this study (denoted as N-flux networks), in which the IP addresses are swapped in and out at a speed normally associated with benign domains. Accordingly, the present study proposes a two-stage FFSN detection scheme in which a data mining algorithm is employed initially to detect possible FFSNs and a shared-domain detection algorithm is then applied to identify the nature of the FFSN through an analysis of its malware connections. The feasibility of the proposed scheme is demonstrated by analyzing five real-world datasets. It is shown that the proposed scheme achieves both a higher detection accuracy and a lower detection delay than existing schemes such as GRADE, Flux-Score, FFBD and SSFD.

Index Terms—Advanced persistent threat (APT), fast-flux service network (FFSN), N-flux, data mining.

[PDF]

Cite: Ci-Bin Jiang, Jung-Shian Li, "Exploring Global IP-Usage Patterns in Fast-Flux Service Networks," Journal of Computers vol. 12, no. 4, pp. 371-379, 2017.

General Information

ISSN: 1796-203X
Frequency: Monthly (2006-2014); Bimonthly (Since 2015)
Editor-in-Chief: Prof. Liansheng Tan
Executive Editor: Ms. Cherry L. Chen
Abstracting/ Indexing: DBLP, EBSCO, DOAJ, ProQuest, INSPEC, ULRICH's Periodicals Directory, WorldCat, CNKI,etc
E-mail: jcp@iap.org
  • Jan 20, 2017 News!

    Vol.12, No.6 has been published with online version.   [Click]

  • Jan 16, 2017 News!

    Vol.12, No.5 has been published with online version.   [Click]

  • Oct 09, 2016 News!

    Vol.12, No.4 has been published with online version.   [Click]

  • Sep 02, 2016 News!

    Vol.11, No.3 has been indexed by EI (Inspec).   [Click]

  • Aug 18, 2016 News!

    Vol.11, No.2 has been indexed by EI (Inspec).   [Click]

  • Read more>>